Regarding this bug, Does the password-recovery disable feature should be disabled in order to exploit this vulnerability?
Determine Whether the Password-Recovery Disable Feature is Enabled
To determine whether the password-recovery disable feature is...