Think of it this way, there is a door as a barrier, they just added a deadbolt lock. Prior the door opened freely, but was a door.
Normally shouldn't have been any harm in curling said URL's/files... but in this instance, yeah did what it did, every time.
Nothing was disclosed to anyone other than account holders, in their inbox, their account name + new password.
Certainly an annoyance, PITA and perhaps access issues for clients.
I'll jump in any time anyone thinks Solus or WHMCS or Cpanel are compromise culrpit and is about to set off mass provider paranoia, pulling of panels, etc. Saw what happened elsewhere with Solus and the shitfest, additional workload on folks and general distrust in segment. If I can be of some use, I try.