It would appear, that when the Admin registers an account for someone, and sets it to send the password, it sends the hash, not the password.
Which is something I'd remove entirely, since e-mails aren't really secure in the first place...
I beg to differ on removing.
However, I would suggest maybe doing like other sites, where the admin does not set password, but the email has link to set one.
Sort of the same link the password reset email has.
I like that way more than plain text passwords around ;)
Fixed, but can't find the issue nor the commit.
About the removal... it requires at least another report as feature discussion. :P