Maybe a security issue @ lostpassword-functions.php

  • Hey guys!


    I've got a mail with a password reset link today. This was sent from my i-MSCP server and inside the email, there is a unknown domain name.



    First of all, I do not know who owns septera.eu. I never seen that domain. And also this domain is not listed in my i-MSCP system.


    So what to do?
    This is a strange situation, because the domain A record points my IP address.
    Better safe than sorry!


    i-MSCP latest git master 22.08.2013 | Debian 6.0

    Edited once, last by beny9512 ().

  • Hello ;


    It's not a security hole. As long as the owner of the mail account (which is receiving the mail) doesn't confirms by clicking on the link, the password will not be reseted.

    badge.php?id=1239063037&bid=2518&key=1747635596&format=png&z=547451206