Results 1 to 2 of 2

URLs to private threads rewritten in subscriptionmail

This is a discussion on URLs to private threads rewritten in subscriptionmail within the Bug Reporting forums, part of the vBSEO SEO Plugin category; I've just come across a bug where private information is disclosed. As administrator with full access I've posted a reply ...

  1. #1
    Junior Member
    Real Name
    Jean-Paul Horn
    Join Date
    Feb 2006
    Location
    Amsterdam, The Netherlands
    Posts
    18
    Liked
    0 times

    URLs to private threads rewritten in subscriptionmail

    I've just come across a bug where private information is disclosed. As administrator with full access I've posted a reply with a link to a private thread. Intentionally I'd changed the url into showthread.php?t=... so the threadtitle wouldn't be visible in the link. Although this works for users viewing the post, the link in the subscriptionmail has been rewritten and includes the threadtitle regardless of the permission of the user who gets the email.
    Last edited by Palmclub; 01-15-2007 at 12:56 PM.

  2. #2
    vBSEO Staff Oleg Ignatiuk's Avatar
    Real Name
    Oleg Ignatiuk
    Join Date
    Jun 2005
    Location
    Belarus
    Posts
    25,744
    Liked
    168 times
    Thank you for reporting!

    /* NOTE: This issue has been resolved. The fix will be distributed with the next vBSEO build. */

Similar Threads

  1. Sitemap alırken hata alıyorum :(
    By erhanerhan_5 in forum Türkçe
    Replies: 9
    Last Post: 11-15-2006, 08:44 AM
  2. i think something is wrong....
    By briansol in forum General Discussion
    Replies: 3
    Last Post: 08-20-2006, 06:10 PM
  3. Replies: 8
    Last Post: 08-15-2006, 04:10 AM
  4. Compression Error
    By Lazer in forum Troubleshooting
    Replies: 19
    Last Post: 03-03-2006, 01:23 PM

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •