In the InvoicePlane login page there is an option to reset a forgotten password. Here you can enter any e-mail address and then a reset link with a token is sent to this e-mail address.
For an unknown e-mail address the reset token will fail but i was wondering if it would not be better or more save to check if an existing e-mail address was entered before sending out the e-mail with the reset token.
Last Update: 18.03.2017
1 Like