Identify the member from the authenticated session, validate each editable field on the server, and use a prepared statement. Do not accept a member ID from a hidden form field as proof that the user may update that account.
<?php
session_start();
$memberId = $_SESSION['member_id'] ?? 0;
$name = trim($_POST['name'] ?? '');
$email = filter_input(INPUT_POST, 'email', FILTER_VALIDATE_EMAIL);
if ($memberId < 1 || $name === '' || !$email) {
exit('Invalid profile data.');
}
$stmt = $pdo->prepare(
'UPDATE members
SET name = :name, email = :email
WHERE id = :id'
);
$stmt->execute([
':name' => $name,
':email' => $email,
':id' => $memberId,
]);
?>
After updating, escape values with htmlspecialchars() when they are rendered into HTML. Add a CSRF token to the form and enforce uniqueness rules for fields such as email addresses at the database level.
| vicky | 24-10-2013 |
| it's nice and great and exactly what i am looking for, i am suggesting about including profile picture for user if you could do that it would be great to see. | |
| Chinedum | 07-03-2018 |
| The download link for the script is not on the page. | |
| Jamie | 09-04-2018 |
| This was exactly what i was looking for. Im hoping to take your system and modify it for a game i am building. Its just so tricky to handle user management. | |
| smo1234 | 14-02-2019 |
| This is part of Membership management script. Download link at the end of the page is there. | |