Project

General

Profile

Actions

Feature #21660

closed

Secure the BE login 3 - The password change facility does not require the user’s current password.

Added by Nikolas Hagelstein over 14 years ago. Updated over 8 years ago.

Status:
Closed
Priority:
Could have
Assignee:
-
Category:
-
Target version:
Start date:
2009-11-24
Due date:
% Done:

0%

Estimated time:
PHP Version:
5.5
Tags:
Complexity:
Sprint Focus:

Description

Currently the password change facility does not require the user’s current password. Due to cross site request forgery an attacker an attacker can change a user’s password if the attacker can entice the user to submit a forged request.

Suggestion:
The current password should be requiered by the password change facillity.

(issue imported from #M12723)

Actions

Also available in: Atom PDF