| PP 5.62: users are able to cheat with identical email address
PP 5.62, stand alone version
i just found out, that users are able to cheat with identical email addresses.
I have in my ACP the option:
"Require unique email addresses for user registration?"
I set this to Yes. But the users are still able to change their mail address afterwards to an email, which exists already in the database.
The user can register normallly, after that he goes into his profile and changes his mail address to another one. With this, he can have unlimited usernames all with the same email address. I tested this with 3 different accounts.
This should not be possible, if I set the ACP option to unique email addresses.
How can I fix this?
|