-
Notifications
You must be signed in to change notification settings - Fork 234
Description
Greetings,
I have enabled 'RequireChangeConfirm' in application.php
However, it doesn't not send confirmation email to the old Email address in order to approve the changes, instead it sends to the new email.
I'm not sure if it supposed to send the confirmation email to the new one, but it shouldn't do this.
Let's imagine this scenario: Let's say someone knows my account credentials, they login to my account in the Control Panel, and deiced to steal my account by changing the email address. They can easily do that by simply filling and submitting the form in /?module=account&action=changemail
My idea is: Before changing email address, a confirmation link is sent to the old/current email address to review and approve the changes, if the account holder decided to decline the changes, then it cancels the operation and deny the changes, and vice versa
Metadata
Metadata
Assignees
Type
Projects
Status
