Infos
    #4831
    Sandra Echinard (sechinard)
    2014-02-28 13:50
    2013-08-22 18:13
    5133
    Details
    CSRF issue
    This prevents to update values in the following pages:
    /account/change_email.php
    /account/change_pwd.php

    It impacts probably all those which are using CSRFTokenSynchronizer::check().
    Other
    Empty
    Empty
    • [ ] enhancement
    • [ ] internal improvement
    Empty
    Stage
    Nicolas Terray (nterray)
    Closed
    2014-02-28
    Attachments
    Empty
    References
    Referenced by request #4831

    Follow-ups

    User avatar
    The issue on /account/change_pw.php has be fixed in 6.11 (see request #6154)

    • Status changed from Under implementation to Closed
    • Close date set to 2014-02-28
    User avatar
    The issue on /account/change_email.php has been fixed in Tuleap 6.4.

    • Status changed from New to Under implementation
    • Assigned to changed from None to Nicolas Terray (nterray)