Restricted content freely available when using ID#
Moderator: Thorsten
Restricted content freely available when using ID#
FAQ entries which are restricted to members of a specific group are freely available to anonymous users when searching for the entry's ID#. Of course this is not easy but since the IDs are sequential it's not too difficult to guess different IDs and perhaps gain access to otherwise restricted content!
Hi,
right... can you add this to the bugtracker?
bye
Thorsten
right... can you add this to the bugtracker?
bye
Thorsten
phpMyFAQ Maintainer and Lead Developer
amazon.de Wishlist
amazon.de Wishlist