Security issue
-
This plugin is not secure because it allows any visitor to the site to modify any user’s options!
All you have to do is build a URL like this:
https://www.example.com/members/the-member-that-will-be-affected/settings/privacy-settings/I’m already using the bp_is_my_profile () function to protect my users. While this serious problem is not solved, in my view.
The idea of the plugin is very good, however it needs some work!
- This topic was modified 6 years, 11 months ago by .
- This topic was modified 6 years, 11 months ago by .
- This topic was modified 6 years, 11 months ago by .
- This topic was modified 6 years, 11 months ago by .
The page I need help with: [log in to see the link]
Viewing 15 replies - 1 through 15 (of 15 total)
Viewing 15 replies - 1 through 15 (of 15 total)
- The topic ‘Security issue’ is closed to new replies.