Other users' mail addresses are revokable.
Affects | Status | Importance | Assigned to | Milestone | |
---|---|---|---|---|---|
Jisko |
Fix Released
|
Medium
|
Marcos Garcia |
Bug Description
jisko v2.0
1.My mail address is changed.
2.URL of the mail that has been sent is put on the message.
3.When the person who is logging it in clicks the URL, the mail address of the person who clicked is changed.
Stop-gap measure
settings.php
case 'config':
if ($_GET['uid'] && $_GET['key']) {
$check = $db->checkEmail
if ($check) {
$newEmail = $db->getEmailFr
$_USER['email'] = $newEmail;
$db-
echo showStatus(
}
}
-------
case 'config':
if ($_GET['uid'] && $_GET['key']) {
$check = $db->checkEmail
if ($check) {
$newEmail = $db->getEmailFr
$_USER['email'] = $newEmail;
$db-
$db-
echo showStatus(
}
}
Changed in jisko: | |
status: | In Progress → Fix Released |
Fixed in last revision.
Sorry about this problem, and thanks for reporting and making Jisko better!
Regards, Marquitox.