Allows to send any user a new password but also see what it is (ie. allows access to any user account). Disabled by default and on Wikimedia wikis, but if some wiki enables it, that's a security catastrophe waiting to happen.
Description
Description
Details
Details
Subject | Repo | Branch | Lines +/- | |
---|---|---|---|---|
Remove passwordreset capture feature | mediawiki/core | master | +26 -134 |
Related Objects
Related Objects
Event Timeline
Comment Actions
Change 321838 had a related patch set uploaded (by Gergő Tisza):
Remove passwordreset capture feature