internal > notifications > Bug (done?)

index.php?go=triggerSendNotifications: security issue/#6669

Summary

done?
Jul 7, 2008
100%
Jul 7, 2008 / array
Nov 14, 2011 / guest
pixtur
 

Attached files

No files uploaded
 
This task does not have any text yet.
Doubleclick here to add some.

Issue report

Major
Always
If user have no notifications to send it shows a message: "Note: No news for <username>".
So using this link anybody can see all users in the system.
Company client can see all other clients etc.
Disable any output if logged user has no administrative rights.
 

4 Comments

pixtur:I have to review this

4 years ago


luchyx:Suggestion

4 years ago

Show output only if a valid user is logged in.

pixtur:fixed

4 years ago

ok, changed this in rev 414

guest:Topher

4 months ago - visible as suggested - Delete

If information were soccer, this would be a gooooaol!