⚠️ Pracivo Security Lab — Open redirect in login, email header injection in contact, username enumeration in reset.
Reset Password
Hint: try valid (alice, bob, admin) and invalid usernames — the error messages are different, revealing which usernames exist.