]> git.ipfire.org Git - thirdparty/bugzilla.git/commitdiff
Bug 670868: (CVE-2011-2978) [SECURITY] Account preferences page trusts user-modifiabl...
authorByron Jones <glob@mozilla.com>
Thu, 4 Aug 2011 20:46:53 +0000 (22:46 +0200)
committerFrédéric Buclin <LpSolit@gmail.com>
Thu, 4 Aug 2011 20:46:53 +0000 (22:46 +0200)
r/a=LpSolit

userprefs.cgi

index 8be6bcdfc8587dba8158a3af1c6be86ed7dc6857..cd5b158f0b792bb404c54565fa2dea40331144a7 100755 (executable)
@@ -84,7 +84,7 @@ sub SaveAccount {
     my $pwd1 = $cgi->param('new_password1');
     my $pwd2 = $cgi->param('new_password2');
 
-    my $old_login_name = $cgi->param('old_login');
+    my $old_login_name = $user->login;
     my $new_login_name = trim($cgi->param('new_login_name'));
 
     if ($user->authorizer->can_change_password