You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Something many users might not know is that when you allow the feature "Reset Password" you need to really really really customize this one uncommon tpl
[[!Login? &sentTpl=`lgnForgotPassSentTpl`]]
Otherwise, any lurker can get any user's email address if the lurker knows a username.
The lurker just has to attempt to reset password by given username.
The unusual default HTML of that tpl is something revealing like this... <p>Your login information has been sent to the email address [[+email]].</p>
The text was updated successfully, but these errors were encountered:
https://github.com/modxcms/Login/blob/master/core/components/login/elements/chunks/lgnforgotpasssenttpl.chunk.tpl
Something many users might not know is that when you allow the feature "Reset Password" you need to really really really customize this one uncommon tpl
[[!Login? &sentTpl=`lgnForgotPassSentTpl`]]
Otherwise, any lurker can get any user's email address if the lurker knows a username.
The lurker just has to attempt to reset password by given username.
The unusual default HTML of that tpl is something revealing like this...
<p>Your login information has been sent to the email address [[+email]].</p>
The text was updated successfully, but these errors were encountered: