Does it really work like that? I would expect you would have to enter an email address, otherwise that might could be an exploit?
You can enter either an email address or a username.
For an email address it will either come back as "
There are no usernames associated with that email."(which is what I kept getting) or if it is a valid address it would email to confirm the reset.
For a username, only the address registered to that username would get the email to confirm a reset. (or to ignore if it was not initiated by that user)
Not sure how/if that could be exploited. Not interested in it anyway, I was not particularly attached to MrB. A few extra letters doesn't bother me