diff --git a/htdocs/resetpassword.php b/htdocs/resetpassword.php index 74160a6..088da23 100644 --- a/htdocs/resetpassword.php +++ b/htdocs/resetpassword.php @@ -26,10 +26,10 @@ $result = "passwordrequired"; } -if (isset($_POST["oldpassword"]) and $_POST["oldpassword"]) { - $oldpassword = $_POST["oldpassword"]; -} else { +if ($audit_admin === "anonymous" and !isset($_POST["oldpassword"]) and !$_POST["oldpassword"]) { $result = "oldpasswordrequired"; +} else { + $oldpassword = $_POST["oldpassword"]; } if (isset($_POST["pwdreset"]) and $_POST["pwdreset"]) {