Vanilla 1 is no longer supported or maintained. If you need a copy, you can get it here.
HackerOne users: Testing against this community violates our program's Terms of Service and will result in your bounty being denied.
Options

blank password login

troppmanntroppmann New
edited March 2008 in Vanilla 1.0 Help
i have a user who is a default moderator on one of my forums who, when logging in, can put any name in the username field, without her password.....hit enter and login in as herself....

i have checked roles and permissions, had cookies on her machine cleared and what not but cant seem to figure out why she is having this behavior....anyone seen this?

i did do a search but didnt find anything which relates to this....thanx in advance for any help....

Comments

  • Options
    That's a huge security hole if it is as you say.

    Perhaps a weird cookie thing happening.

    You might include a few more details like browser and version...
This discussion has been closed.