Support for Drupal 7 is ending on 5 January 2025—it’s time to migrate to Drupal 10! Learn about the many benefits of Drupal 10 and find migration tools in our resource center.
There is a syntax error in email_verify.check.inc on line 28.
In addition, the access permissions on email_verify page pose a real security/privacy risk since anyone with view access content permission (everyone) can view all other user email addresses. The path should be set to:
admin/users/users/email_verify
and the access arguments should be set to:
administer users
Attached is patch which fixes this (patched against 6.x-1.x-dev 2009-Mar-19).
Comment | File | Size | Author |
---|---|---|---|
email_verify-admin-users.patch | 954 bytes | john.money |
Comments
Comment #1
dbr CreditAttribution: dbr commentedThanks for the fixes.
I never documented the verify function, so the risk is smaller, but indeed it can easily be found in the code, so it's safer like this.
The patch is applied to the 6.x-1.x-dev branch.
Comment #2
dbr CreditAttribution: dbr commentedThis is now fixed in 6.x-1.1
Comment #3
dbr CreditAttribution: dbr commented