[fixed] News: no permission check in action.editarticle.php

The members of the Dev team will place issues here that they consider to be solved.
Post Reply
dwave
Forum Members
Forum Members
Posts: 39
Joined: Mon Aug 13, 2007 11:15 am
Location: Israel

[fixed] News: no permission check in action.editarticle.php

Post by dwave »

Steps to reproduce:

1. Open Browser, enter URL:
[DELETED]
Last edited by dwave on Fri Aug 26, 2011 3:35 pm, edited 1 time in total.
uniqu3

Re: News: no permission check in action.editarticle.php

Post by uniqu3 »

Oh confirmed, reproduced.
dwave
Forum Members
Forum Members
Posts: 39
Joined: Mon Aug 13, 2007 11:15 am
Location: Israel

Re: News: no permission check in action.editarticle.php

Post by dwave »

Previous versions of CMS Made Simple are also affected.
Very nice.
Try the submit button :)
cb2004
Power Poster
Power Poster
Posts: 317
Joined: Wed Jul 04, 2007 3:39 pm

Re: News: no permission check in action.editarticle.php

Post by cb2004 »

Wow. Lets get this removed from the forum.
RonnyK
Support Guru
Support Guru
Posts: 4962
Joined: Wed Oct 25, 2006 8:29 pm
Location: Raalte, the Netherlands

Re: News: no permission check in action.editarticle.php

Post by RonnyK »

this one is fixed in SVN for 1.10.

Ronny
User avatar
dc2
Forum Members
Forum Members
Posts: 116
Joined: Tue Jun 02, 2009 8:21 pm

Re: News: no permission check in action.editarticle.php

Post by dc2 »

Shouldn't this also be (hot)fixed for - at least - 1.9 too?
cb2004
Power Poster
Power Poster
Posts: 317
Joined: Wed Jul 04, 2007 3:39 pm

Re: News: no permission check in action.editarticle.php

Post by cb2004 »

Most definitely.
dwave
Forum Members
Forum Members
Posts: 39
Joined: Mon Aug 13, 2007 11:15 am
Location: Israel

Re: News: no permission check in action.editarticle.php

Post by dwave »

cb2004 wrote:Wow. Lets get this removed from the forum.
I agree. I edited my initial post and removed the URL. It was stupid to post it here but I thought only 1.10 was affected.
Post Reply

Return to “Closed Issues”