Page 1 of 1

[fixed] News: no permission check in action.editarticle.php

Posted: Thu Aug 25, 2011 10:10 pm
by dwave
Steps to reproduce:

1. Open Browser, enter URL:
[DELETED]

Re: News: no permission check in action.editarticle.php

Posted: Fri Aug 26, 2011 7:01 am
by uniqu3
Oh confirmed, reproduced.

Re: News: no permission check in action.editarticle.php

Posted: Fri Aug 26, 2011 1:51 pm
by dwave
Previous versions of CMS Made Simple are also affected.
Very nice.
Try the submit button :)

Re: News: no permission check in action.editarticle.php

Posted: Fri Aug 26, 2011 2:58 pm
by cb2004
Wow. Lets get this removed from the forum.

Re: News: no permission check in action.editarticle.php

Posted: Fri Aug 26, 2011 3:04 pm
by RonnyK
this one is fixed in SVN for 1.10.

Ronny

Re: News: no permission check in action.editarticle.php

Posted: Fri Aug 26, 2011 3:27 pm
by dc2
Shouldn't this also be (hot)fixed for - at least - 1.9 too?

Re: News: no permission check in action.editarticle.php

Posted: Fri Aug 26, 2011 3:31 pm
by cb2004
Most definitely.

Re: News: no permission check in action.editarticle.php

Posted: Fri Aug 26, 2011 3:35 pm
by dwave
cb2004 wrote:Wow. Lets get this removed from the forum.
I agree. I edited my initial post and removed the URL. It was stupid to post it here but I thought only 1.10 was affected.