Open LukasReschke opened 3 years ago
Reference https://hackerone.com/reports/1169335
Should only be reported if the user backend allows the user to change their password.
Reference https://hackerone.com/reports/1169335