]> git.ipfire.org Git - thirdparty/bugzilla.git/commitdiff
Bug 670868: (CVE-2011-2978) [SECURITY] Account preferences page trusts user-modifiabl...
authorByron Jones <glob@mozilla.com>
Thu, 4 Aug 2011 20:44:48 +0000 (22:44 +0200)
committerFrédéric Buclin <LpSolit@gmail.com>
Thu, 4 Aug 2011 20:44:48 +0000 (22:44 +0200)
r/a=LpSolit

userprefs.cgi

index 009361324ae5a7a27be1b2ca1feeb9d025f1ad69..f411326a241b7ba1f16d9c4ae0ed069ddb939cfb 100755 (executable)
@@ -85,7 +85,7 @@ sub SaveAccount {
     my $pwd1 = $cgi->param('new_password1');
     my $pwd2 = $cgi->param('new_password2');
 
-    my $old_login_name = $cgi->param('old_login');
+    my $old_login_name = $user->login;
     my $new_login_name = trim($cgi->param('new_login_name'));
 
     if ($user->authorizer->can_change_password