Vulnerable Systems:
* Mandrill 7.x-1.x versions prior to 7.x-1.2.
This module enables you to send emails using an external gateway and by default logs the contents of the messages. An attacker who gains access to the Mandrill dashboard can trigger password reset emails from the Drupal site, get the reset links from the Mandrill logs, and take over an account.