Bernhard, in msg4367 you seem to think that someone needs to get hold of
the sent mail to retrieve the address.
The email address is displayed as "Email sent to" in
the web interface, even when just the username was entered in the
password reset form.

I consider this an information leak as it does not even use the
permission system, therefore upgrading to type security and severity
normal. I would even think that a higher severity level might be
