diff --git a/security/PasswordEncryptor.php b/security/PasswordEncryptor.php index a720d445b..d9a08b3c3 100644 --- a/security/PasswordEncryptor.php +++ b/security/PasswordEncryptor.php @@ -161,7 +161,7 @@ class PasswordEncryptor_PHPHash extends PasswordEncryptor { */ class PasswordEncryptor_LegacyPHPHash extends PasswordEncryptor_PHPHash { function encrypt($password, $salt = null, $member = null) { - $password = parent::encrypt($password, $member, $salt); + $password = parent::encrypt($password . $salt, $member, $salt); // Legacy fix: This shortening logic is producing unpredictable results. //