interface/web/login/index.php
@@ -114,7 +114,7 @@ $sql = "SELECT * FROM sys_user WHERE USERNAME = '$username'"; $user = $app->db->queryOneRecord($sql); if($user && $user['active'] == 1) { if($user) { $saved_password = stripslashes($user['passwort']); @@ -122,7 +122,7 @@ //* The password is crypt-md5 encrypted $salt = '$1$'.substr($saved_password,3,8).'$'; if(crypt($passwort,$salt) != $saved_password) { if(crypt(stripslashes($passwort),$salt) != $saved_password) { $user = false; } } else {