mirror of
https://github.com/silverstripe/silverstripe-framework
synced 2024-10-22 14:05:37 +02:00
[CVE-2023-32302] Require password field to be non-empty
This commit is contained in:
parent
cb7be276e7
commit
7b21b38ac4
@ -731,7 +731,7 @@ class Member extends DataObject
|
|||||||
$password->setRequireExistingPassword(true);
|
$password->setRequireExistingPassword(true);
|
||||||
}
|
}
|
||||||
|
|
||||||
$password->setCanBeEmpty(true);
|
$password->setCanBeEmpty(false);
|
||||||
$this->extend('updateMemberPasswordField', $password);
|
$this->extend('updateMemberPasswordField', $password);
|
||||||
|
|
||||||
return $password;
|
return $password;
|
||||||
|
Loading…
Reference in New Issue
Block a user