[wp-trac] [WordPress Trac] #23488: WordPress incorrectly escapes passwords when emailing to new users

WordPress Trac noreply at wordpress.org
Sat Feb 16 20:20:03 UTC 2013


#23488: WordPress incorrectly escapes passwords when emailing to new users
-----------------------------+--------------------------
 Reporter:  bklang           |       Type:  defect (bug)
   Status:  new              |   Priority:  normal
Milestone:  Awaiting Review  |  Component:  General
  Version:  3.5.1            |   Severity:  normal
 Keywords:                   |
-----------------------------+--------------------------
 I created a new user account today whose password contained a single-quote
 ( ' ).  When the new user received the password it was escaped with a
 backslash ( \' ).  This caused him to be unable to log in, not knowing he
 should remove the backslash.

 Passwords sent to users should not be escaped.

-- 
Ticket URL: <http://core.trac.wordpress.org/ticket/23488>
WordPress Trac <http://core.trac.wordpress.org/>
WordPress blogging software


More information about the wp-trac mailing list