Craft CMS before 2.6.2976 does not prevent modification of the URL in a forgot-password email message.
mitre·CWE-640·Published 2017-05-01