#1930 remind pass. error if username instead of UserName

v1.8.5
open
nobody
5
2012-12-08
2005-04-02
Xavier de Pedro
No

Hi: This looks like a bug, that happened to several
users in my site along last month.

Lets say a person's username in Tiki is UserName. That
person requests a remind of his/her password through
"tiki-remind_password.php". But the username he/she
introduces in the text box is: username (all lower
cases) instead of UserName (two uper case letters).

There seems to be an email sent to nobody in the "To:"
field, with "username" within the text of the message,
and a new password for that person, even if that person
never received the message.
Example of message below, from a tiki site installed at
ourproject.org.

================
From: Mail Delivery System <Mailer-Daemon@ourproject.org>
> To: www-data@ourproject.org
> Subject: Mail failure - no recipient addresses
> Date: Fri, 01 Apr 2005 12:34:57 +0200
>
> A message that you sent contained no recipient
addresses, and therefore no
> delivery could be attempted.
>
> ------ This is a copy of your message, including all
the headers. ------
>
> Received: from www-data by mailhost.ourproject.org
with local (Exim 3.36 #1 (Debian))
> id 1DHJUP-0005CX-00; Fri, 01 Apr 2005 12:34:57 +0200
> To:
> Subject: La teva informació de compte de Tiki per a
uniwiki.aia.ourproject.org
> From: xavidp@porthos.bio.ub.es
> Content-type: text/plain;charset=utf-8
> Message-Id: <E1DHJUP-0005CX-00@mailhost.ourproject.org>
> Date: Fri, 01 Apr 2005 12:34:57 +0200
>
>
> Hola, neuspavon algú de uniwiki.aia.ourproject.org
requested a reminder of the password for the
> compte neuspavon, since this is your registered email
address we inform that the
> password for this account is XXXxX
===============================

Discussion