I doubt it will do any harm besides filling up your mail queue. There's not a whole lot to do against it since it's just a public page.
Have you checked the access logs for GET/POST requests sent to login.php?do=lostpw? Maybe you can get some more information regarding who did it by looking at the access logs.
No members have liked this post.
|