The flaw (CVE-2023-7028) stems from the fact that user account password reset emails can be delivered to unverified email addresses.