change error message when changing username

Bug #1772774 reported by Cecilia Vela Gurovic
256
This bug affects 1 person
Affects Status Importance Assigned to Milestone
Mahara
Fix Released
High
Cecilia Vela Gurovic
17.04
Fix Released
High
Unassigned
17.10
Fix Released
High
Unassigned
18.04
Fix Released
High
Unassigned
18.10
Fix Released
High
Cecilia Vela Gurovic

Bug Description

When trying to change your username, if it is already taken the error message is displayed:

Sorry, this username is already taken.

We should not be giving information about which usernames are taken.
We should change it to something a more general message.

CVE References

Changed in mahara:
status: New → Confirmed
importance: Undecided → High
Revision history for this message
Cecilia Vela Gurovic (ceciliavg) wrote :
information type: Private Security → Public
information type: Public → Public Security
Revision history for this message
Kristina Hoeppner (kris-hoeppner) wrote :

CVE-2018-11565

To post a comment you must log in.
This report contains Public Security information  
Everyone can see this security related information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.