Skip to content

Change email confirmation does not work as intended #289

@earnestinence

Description

@earnestinence

Greetings,

I have enabled 'RequireChangeConfirm' in application.php

However, it doesn't not send confirmation email to the old Email address in order to approve the changes, instead it sends to the new email.

I'm not sure if it supposed to send the confirmation email to the new one, but it shouldn't do this.

Let's imagine this scenario: Let's say someone knows my account credentials, they login to my account in the Control Panel, and deiced to steal my account by changing the email address. They can easily do that by simply filling and submitting the form in /?module=account&action=changemail

My idea is: Before changing email address, a confirmation link is sent to the old/current email address to review and approve the changes, if the account holder decided to decline the changes, then it cancels the operation and deny the changes, and vice versa

image

Metadata

Metadata

Assignees

No one assigned

    Type

    No type

    Projects

    Status

    New Items

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions