diff --git a/api_views/users.py b/api_views/users.py index 172540a..95a1837 100644 --- a/api_views/users.py +++ b/api_views/users.py @@ -184,6 +184,9 @@ def update_password(username): else: if request_data.get('password'): if vuln: # Unauthorized update of password of another user + if username != resp.get('sub'): + return Response(error_message_helper("You are not authorized to change the password of another user"), + 403, mimetype="application/json") user = User.query.filter_by(username=username).first() if user: user.password = request_data.get('password')