index.php?go=triggerSendNotifications: security issue / #6669

Summary

v0.0803 - bug fixes
open
Jul 7, 2008
Jul 7, 2008 / array
Jul 7, 2008 / cody-somerville
pixtur
 

Attached files

No files uploaded

Issue report

Major
Always
If user have no notifications to send it shows a message: "Note: No news for <username>".
So using this link anybody can see all users in the system.
Company client can see all other clients etc.
Disable any output if logged user has no administrative rights.
 

Comment / Update