View Issue Details

IDProjectCategoryView StatusLast Update
0007037mantisbtsecuritypublic2006-05-07 03:51
Reportervboctor Assigned Tovboctor  
PrioritynormalSeveritymajorReproducibilityalways
Status closedResolutionfixed 
Product Version1.0.2 
Fixed in Version1.0.3 
Summary0007037: Port: Login with disabled account possible
Description

With this bug it is possible to login although an account is disabled.

I go to www.myserver.com/mantis/ and click "Lost your password?" and then enter the data of my disabled account.
No I get an email with a password reset link. When I click it, I see the login-screen, but when I go then back to www.myserver.com/mantis/:
Voila! I'm logged in with my disabled account!

TagsNo tags attached.

Relationships

child of 0007006 closedvboctor Login with disabled account possible 
child of 0006971 closedvboctor Mantis 1.0.3 Release 

Activities

There are no notes attached to this issue.