1
0
Fork 0

Merge pull request #7725 from dew-git/develop

Fix security vulnerabilities.
This commit is contained in:
Hypolite Petovan 2019-10-11 14:48:07 -04:00 committed by GitHub
commit 27eaffd7fb
No known key found for this signature in database
GPG key ID: 4AEE18F83AFDEB23
9 changed files with 454 additions and 334 deletions

View file

@ -1,4 +1,5 @@
<?php
/**
* @file mod/lostpass.php
*/
@ -27,7 +28,7 @@ function lostpass_post(App $a)
$a->internalRedirect();
}
$pwdreset_token = Strings::getRandomName(12) . mt_rand(1000, 9999);
$pwdreset_token = Strings::getRandomName(12) . random_int(1000, 9999);
$fields = [
'pwdreset' => $pwdreset_token,