Comment by paxys

11 hours ago

Am I missing something? The source they shared is a screenshot of a password reset email, which anyone can trigger if they have the email address of the account.

You don't even need the email address. The account name is enough to start the password request.