When users are requesting password reset it is
showing users email address without any validation
and giving the below "Message".It would be better
if it can atleast hide the emailid and display
@domain.com on this page
or
before displaying this message do some validation for
the user.
------------------Message Start---------------------
Hello...
An email with your new password was sent to the
address (EMAILID@DOMAIN.COM).
Please check your email account; you should receive
our message soon.
Recommendation:
You should login to this site with your new password
as soon as possible, and you should change your
password to maintain your data's security.
------------------Message Start-----------------------