The administrative page, block/add, doesn't check whether or not a user has access to create a bean of a specific type before generating the list.
| Comment | File | Size | Author |
|---|---|---|---|
| #1 | bean-permissions-1839966-1.patch | 1.01 KB | ultimateboy |
The administrative page, block/add, doesn't check whether or not a user has access to create a bean of a specific type before generating the list.
| Comment | File | Size | Author |
|---|---|---|---|
| #1 | bean-permissions-1839966-1.patch | 1.01 KB | ultimateboy |
Comments
Comment #1
ultimateboy commentedComment #2
indytechcook commentedThanks! http://drupal.org/commitlog/commit/22232/303c4e7cbcd2a0285a3b965f62221b0...
I'd almost consider this a security issue.