HomeDefault status
unaffected
3.9.0-5.4.5
affected
6.0.0-6.1.0
affected
Description
The password and username reset features created plain http links for https connections if the "Force SSL" flag wasn't explicitly set.
Product status
3.9.0-5.4.5
6.0.0-6.1.0
Credits
@ZeroXJacks, https://github.com/ZeroXJacks
References
developer.joomla.org/...ssword-and-username-reset-links.html