From becaee046e73284d74aadaacb82d40bd6386786c Mon Sep 17 00:00:00 2001 From: =?utf8?q?Joshua=20R=C3=BCsweg?= Date: Sun, 14 Jun 2020 17:02:00 +0200 Subject: [PATCH] Improve \hash_equals call MIME-Version: 1.0 Content-Type: text/plain; charset=utf8 Content-Transfer-Encoding: 8bit Co-authored-by: Tim Düsterhus --- .../install/files/lib/form/RegisterActivationForm.class.php | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/wcfsetup/install/files/lib/form/RegisterActivationForm.class.php b/wcfsetup/install/files/lib/form/RegisterActivationForm.class.php index e01d196f3b..5a12caa2ae 100644 --- a/wcfsetup/install/files/lib/form/RegisterActivationForm.class.php +++ b/wcfsetup/install/files/lib/form/RegisterActivationForm.class.php @@ -83,7 +83,7 @@ class RegisterActivationForm extends AbstractForm { } // check given activation code - if (!\hash_equals($this->activationCode, $this->user->emailConfirmed)) { + if (!\hash_equals($this->user->emailConfirmed, $this->activationCode)) { throw new UserInputException('activationCode', 'invalid'); } -- 2.20.1