forgotten_password of the file index.php of the component Parameter Handler. The manipulation of the argument email results in sql injection.This vulnerability is known as CVE-2019-25641. It is possible to launch the attack remotely. Furthermore, an exploit is available.
SOCIAL SHARE CARD GENERATOR