We just got an e-mail by a white-hat hacker that saw some issues with our CS-Cart installation.
There were 2 issues which i can’t seem to find a solution for:
The option ‘forgot password’ should be protected by the ReCaptcha plugin, but it seems people can still brute force this system and use it to e-mailbomb other e-mailaddresses.
the user registration password requirements/policy only allows for lenght and the requirement of letters and number, but not an option to require special-characters.
This makes bruteforcing the password way easier than when customers are required to also use special-characters.
How can we address these issues or is there already a solution to these issues I haven’t found yet?