View Issue Details

IDProjectCategoryView StatusLast Update
0008335mantisbtsecuritypublic2013-10-27 08:15
Reportervboctor Assigned Tovboctor  
PrioritynormalSeverityminorReproducibilityhave not tried
Status closedResolutionduplicate 
Product Version1.2.15 
Summary0008335: Changing password should verify that user knows current password
Description

It is a common practice that when a user attempts to change his/her password, they have to confirm their knowledge of the current password. This protects against someone using the computer from changing passwords. This is specifically important with the Mantis being typically used with long sessions (i.e. cookies don't expire quickly or never expire).

TagsNo tags attached.

Relationships

duplicate of 0014486 closedvboctor Secure session login is false security while changing password does not require old password 

Activities

ErikRoelofs

ErikRoelofs

2012-08-30 10:10

reporter   ~0032729

This is especially important since the 'Manage' pages all require you to re-enter your password for safety reasons, but anyone can simply change the current user's password to something else to gain access to the Manage section anyway.

This probably requires a higher priority.