View Issue Details

IDProjectCategoryView StatusLast Update
0010624mantisbtsecuritypublic2009-10-07 14:19
Reporterdhx Assigned Todhx  
PriorityimmediateSeveritymajorReproducibilityalways
Status closedResolutionfixed 
Product Version1.2.0rc1 
Target Version1.2.0rc2Fixed in Version1.2.0rc2 
Summary0010624: Anyone can reset the account preferences of any other user
Description

account_prefs_reset.php does not perform ANY checks to ensure that the current user is authorised the reset the preferences on the target account. It is currently possible for anonymous users to reset the preferences of any other account that they know the username of (ie. anyone).

TagsNo tags attached.

Activities

There are no notes attached to this issue.