From 2995d9319cddc66d3fa3e9c1e75c7e216b13006e Mon Sep 17 00:00:00 2001 From: Sebastien Barre Date: Sat, 1 Nov 2014 09:36:59 -0400 Subject: [PATCH] Prepend model alias for safety --- lib/Cake/Controller/Component/Auth/BaseAuthenticate.php | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/lib/Cake/Controller/Component/Auth/BaseAuthenticate.php b/lib/Cake/Controller/Component/Auth/BaseAuthenticate.php index 9c87cfa2abd..77629ee390d 100644 --- a/lib/Cake/Controller/Component/Auth/BaseAuthenticate.php +++ b/lib/Cake/Controller/Component/Auth/BaseAuthenticate.php @@ -109,7 +109,7 @@ protected function _findUser($username, $password = null) { $userFields = $this->settings['userFields']; if ($password !== null && $userFields !== null) { - $userFields[] = $fields['password']; + $userFields[] = $model . '.' . $fields['password']; } $result = ClassRegistry::init($userModel)->find('first', array(