reset.php in DomainMOD 4.13.0 uses insufficient entropy for password reset requests, leading to account takeover.