#11232 fixed vulnerability when user reset password

This commit is contained in:
Daniel Cebrian 2023-05-16 12:51:03 +02:00
parent 018f024815
commit 64f8113506
1 changed files with 1 additions and 0 deletions

View File

@ -797,6 +797,7 @@ if (isset($config['id_user']) === false) {
$pass2 = get_parameter_post('pass2');
$id_user = get_parameter_post('id_user');
$db_reset_pass_entry = false;
if (empty($reset_hash) === false) {
$hash_data = explode(':::', $reset_hash);
$id_user = $hash_data[0];