View Issue Details

IDProjectCategoryView StatusLast Update
0004198mantisbtsecuritypublic2006-10-09 11:55
Reporterthraxisp Assigned Tothraxisp  
PrioritynormalSeveritytweakReproducibilityalways
Status closedResolutionfixed 
PlatformX86OSWindowsOS VersionWin2K
Summary0004198: Realname can duplicate a username
Description

A user can pick a "realname" that duplicates an existing "username". Username is a unique field, but there is no checking / enforcement on the realname field.

This a malicious user can chose a realname that replicates someone elses username (e.g., administrator) and pose as them.

TagsNo tags attached.

Relationships

child of 0003975 closedthraxisp Realname vs username in email history 

Activities

thraxisp

thraxisp

2004-07-30 16:12

reporter   ~0006481

resolved in changes made for 0003975. Requesting a realname that duplicated a username will fail.