Closed (fixed)
Project:
RSVP
Version:
5.x-1.1
Component:
Code
Priority:
Critical
Category:
Bug report
Assigned:
Reporter:
Created:
25 Jun 2007 at 05:48 UTC
Updated:
1 Jul 2007 at 07:14 UTC
Hi,
Great module! I just came accross a potential security issue in this module. I have a web site for members only where members join with invitation.
I observed when a new user wants to joint the site, and the account sign-up screen is presented, the RSVP tab is present and allows access to the RSVP events, even if the user is just a visitor. I only allowed access to 'Own RSVP's for members only.
See URL below (for user '0', unregistered visitors) the content of the RSVP is not denied, but the tab is displayed.
http://www.mysite.com/user/0/rsvp
I think this is a security bug.
Cheers,
Val
Comments
Comment #1
owahab commentedComment #2
owahab commentedA new release 1.1 will fix this issue among some other issues.
Thanks for your contribution.
Comment #3
owahab commented