I've just come across a bug where private information is disclosed. As administrator with full access I've posted a reply with a link to a private thread. Intentionally I'd changed the url into showthread.php?t=... so the threadtitle wouldn't be visible in the link. Although this works for users viewing the post, the link in the subscriptionmail has been rewritten and includes the threadtitle regardless of the permission of the user who gets the email.


LinkBack URL
About LinkBacks






Reply With Quote