Security Advisories (1)
CPANSA-Jifty-2011-01 (2011-03-17)

The path as passed in the fragment request data structure was used verbatim in the dispatcher and other locations. This possibly allowed requests to walk around ACLs by requesting '/some/safe/place/../../../dangerous' as a fragment.

NAME

Jifty::Plugin::Authentication::Password::Action::SendPasswordReminder - send a link to reset a password

arguments

The field for SendLostPasswordReminder is:

address: the email address

setup

Create an empty user object to work with

validate_address

Make sure there's actually an account by that name.

take_action

Send out a Reminder email giving a link to a password-reset form.