Value Truncation Still Unchecked in registration.php
|Reported by:||miqrogroove||Owned by:|
Functions such as username_exists() fail to perform sanity checks against the storage schema. As a result, it is possible to register multiple users with the same username, if the length is greater than or equal to the username field size. Only the first user can login, however anyone re-registering that username can impersonate the first user to reset their password.