You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
In the latest v6.0.0 version, the endpoint /api/settings/sendEmailCode has a logic issue. The error message indicates that the email has already been registered, and there are no security measures such as rate limiting or CSRF protection. This allows attackers to exploit this error message to brute-force registered users' emails, thereby leaking the email addresses of registered users.