#117 JS in MD5 loginform files

7.4pre1
open
nobody
5
2003-03-30
2003-03-30
No

You use in crloginform.ihtml and crcloginform.ihtml files
the following thing for not submitting first form but submit
only hidden one:

onSubmit="doChallengeResponse()"

This code will not stop submitting first form. You should
use this one code instead of:

onSubmit="return doChallengeResponse()"

I found this error because I needed to put username in a
cookie after authentication and it was failed in loginform
files listed above. Then I discovered that it's happend
because there was submitted 'username' twice (from
first and second form).

By default this error is invisible. Only when you make
some changes in login form (saving username in
cookies, adding some additional fields, etc) you can
reach it.

Discussion