AbleCommerce Forums
»
AbleCommerce
»
AbleCommerce 9 Bug Reports
»
B5867 Changing password allows new password to be same as old
Rank: Advanced Member
Groups: Developers
Joined: 11/7/2018(UTC) Posts: 303
Thanks: 21 times Was thanked: 5 time(s) in 5 post(s)
|
I stumbled across this when I locked myself out. I got in via creating a new user, then adding that user to the admin group in database- just explaining why I ran across this. Once I was in, I changed the password for the original admin user to the same password several times. It never checked to see if the password was different from before. Isn't that required for PCI compliance? Last 4 passwords or something?
|
|
|
|
Rank: Advanced Member
Groups: Administrators, Developers, Registered, HelpDesk, System, Admin Joined: 10/18/2018(UTC) Posts: 183
Thanks: 1 times Was thanked: 6 time(s) in 6 post(s)
|
Hi Judy, I was just logged out of a client's site due to the 30-day expiration and was not able to reuse the same password. Is there any additional information you can provide to replicate the issue? 2019-11-26_15-19-20.png (36kb) downloaded 0 time(s). |
|
|
|
|
Rank: Advanced Member
Groups: Developers
Joined: 11/7/2018(UTC) Posts: 303
Thanks: 21 times Was thanked: 5 time(s) in 5 post(s)
|
Sorry I wasn't clear. I did this in the admin user account, Change password link.
|
|
|
|
AbleCommerce Forums
»
AbleCommerce
»
AbleCommerce 9 Bug Reports
»
B5867 Changing password allows new password to be same as old
Forum Jump
You cannot post new topics in this forum.
You cannot reply to topics in this forum.
You cannot delete your posts in this forum.
You cannot edit your posts in this forum.
You cannot create polls in this forum.
You cannot vote in polls in this forum.
Important Information:
The AbleCommerce Forums uses cookies. By continuing to browse this site, you are agreeing to our use of cookies.
More Details
Close