[ticket/security-272] Use strtolower for actkey

SECURITY-272
This commit is contained in:
Marc Alexander 2021-12-21 21:19:38 +01:00
parent 33a789e030
commit 9bc98278fe
No known key found for this signature in database
GPG key ID: 50E0D2423696F995

View file

@ -363,7 +363,7 @@ class ucp_register
$config['require_activation'] == USER_ACTIVATION_SELF ||
$config['require_activation'] == USER_ACTIVATION_ADMIN) && $config['email_enable'])
{
$user_actkey = gen_rand_string(32);
$user_actkey = strtolower(gen_rand_string(32));
$user_type = USER_INACTIVE;
$user_inactive_reason = INACTIVE_REGISTER;
$user_inactive_time = time();