MantisBT: master-2.27 21e9fbed

Author Committer Branch Timestamp Parent
dregad dregad master-2.27 2025-10-26 14:21 master-2.27 966554a1
Affected Issues  0036005: CVE-2025-55155: Lack of verification when changing a user's email address
Changeset

Verify new email after email change

Fixes 0036005, CVE-2025-55155, GHSA-q747-c74m-69pr

mod - account_page.php Diff File
mod - account_update.php Diff File
mod - api/soap/mc_account_api.php Diff File
mod - core/commands/UserUpdateCommand.php Diff File
mod - core/constant_inc.php Diff File
mod - core/email_api.php Diff File
mod - core/print_api.php Diff File
mod - core/string_api.php Diff File
mod - core/tokens_api.php Diff File
mod - core/user_api.php Diff File
mod - lang/strings_english.txt Diff File
mod - lost_pwd.php Diff File
mod - manage_user_edit_page.php Diff File
mod - manage_user_page.php Diff File
mod - verify.php Diff File
add - verify_email.php Diff File