Page naming security bug
-
If the page title is more than one word, it is easy to bypass the security. If the page name uses “-” in between the words then you can access the page by using a blank space. This also works the other way – if the title has spaces, you can access the page using dashes in their place without authenticating. The immediate solution is that any page requiring authentication cannot use space or dash. Ideally the solution would be for both formats to be included for every page that is added to the private pages list.
Viewing 12 replies - 1 through 12 (of 12 total)
Viewing 12 replies - 1 through 12 (of 12 total)
- The topic ‘Page naming security bug’ is closed to new replies.