When creating a new account in Joomla!, the software sends an e-mail with the data of the user (including the password). However, if the server is not setup correctly (to send e-mails), the site admin will receive a
return message like (similar) this:
Hello XXX,
Thank you for registering at YYY. Your account is created and must be activated before youcan use it.
To activate the account click on the following link or copy-paste it in your browser:
Activation link here.
After activation you may login to YYY using the following username and password.
- Username: myusernamehere
- Password: mypasswordhere
Best Regards,
YYY
The major issue here is that any bad site admin, by simply miss-configuring the e-mail server, would be able to see the password of anyone who registers in his/her web site.
I honestly think, this is a major drawback in the security of Joomla! and usually no passwords should be send via e-mail ever. The post is provoked due to a accident crash of my mail server and receipt of about 10 e-mails like this today, with the passwords of the people who registered.
What is your opinion?
You need to be a member of All Together, As A Whole to add comments!
Join All Together, As A Whole