Resolved vulnerability where user could assign himself admin permissions or activation even without email verification
This commit is contained in:
parent
474c0fba57
commit
bf576d7a67
1 changed files with 1 additions and 1 deletions
|
@ -106,7 +106,7 @@ class Auth
|
|||
if ($result) {
|
||||
$request['verify_token'] = $randomToken;
|
||||
$request['password'] = $this->hash($request['password']);
|
||||
$db->insert('users', array_keys($request), $request);
|
||||
$db->insert('users', ['email', 'password', 'username', 'verify_token'], [$request['email'], $request['password'], $request['username'], $request['verify_token']]);
|
||||
$this->redirect('login');
|
||||
}
|
||||
|
||||
|
|
Loading…
Reference in a new issue