From 5dfd38740a939f0e3b315ce5b5253285b9a01474 Mon Sep 17 00:00:00 2001 From: Byron Jones Date: Thu, 4 Aug 2011 22:46:53 +0200 Subject: [PATCH] Bug 670868: (CVE-2011-2978) [SECURITY] Account preferences page trusts user-modifiable field for obtaining current e-mail address r/a=LpSolit --- userprefs.cgi | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/userprefs.cgi b/userprefs.cgi index 8be6bcdfc8..cd5b158f0b 100755 --- a/userprefs.cgi +++ b/userprefs.cgi @@ -84,7 +84,7 @@ sub SaveAccount { my $pwd1 = $cgi->param('new_password1'); my $pwd2 = $cgi->param('new_password2'); - my $old_login_name = $cgi->param('old_login'); + my $old_login_name = $user->login; my $new_login_name = trim($cgi->param('new_login_name')); if ($user->authorizer->can_change_password -- 2.47.2