Bug Title - Log-in Recovery Exploit
Universe - Any
Bug Description - You can lock out a player from his account if you know his/her email.
How to repeat - Go to log-in recovery and input their email. The password of the account tied to that email will automatically be reset.
I tried it on my own account resetting the password every few mins for 15 minutes. I think you can go on longer.
Forum mods can find out the email tied to your forum account although not the one you use in-game.
Time it happened - Tried it and reported it on the first 2 months of ZE.
P.S.
I guess it does not really matter if nobody knows your email.
[Implemented] Secure Recover Password - new page
#1I am a liar in every debate
I rule the forces that fuel your hate
when the fire in your heart leaves and comes to an end
then quietly I'll go to sleep
I rule the forces that fuel your hate
when the fire in your heart leaves and comes to an end
then quietly I'll go to sleep