mahara-contributors team mailing list archive
-
mahara-contributors team
-
Mailing list archive
-
Message #46100
[Bug 1203924] Re: Username enumeration vulnerability via login & password reset screens
This is now being handled by Bug 1728473
** Changed in: mahara
Status: Confirmed => Won't Fix
--
You received this bug notification because you are a member of Mahara
Contributors, which is subscribed to Mahara.
Matching subscriptions: Subscription for all Mahara Contributors -- please ask on #mahara-dev or mahara.org forum before editing or unsubscribing it!
https://bugs.launchpad.net/bugs/1203924
Title:
Username enumeration vulnerability via login & password reset screens
Status in Mahara:
Won't Fix
Bug description:
A user enumeration vulnerability means that an attacker can get a list
of legal usernames and/or email addresses from the site. A
"bruteforce" user enumeration vulnerability means that if they have a
list of potential usernames and/or email addresses, they can verify
whether or not each of them is registered with an account in the site.
The Mahara password reset page is vulnerable to this. You can simply
go in to https://mahara.org/forgotpass.php and enter username or email
after username or email, and get a friendly response indicating
whether each one is registered with a user in the site or not.
To manage notifications about this bug go to:
https://bugs.launchpad.net/mahara/+bug/1203924/+subscriptions
References