Menu

#3 Un-Private Links

open
Nitrofox
Security (2)
5
2005-07-14
2005-07-14
Nitrofox
No

When viewing a private page that you do not have permissions for,
you can still see the sublinks contained within that private page.

Discussion

  • Nitrofox

    Nitrofox - 2005-07-14

    Logged In: YES
    user_id=1208250

    The links being shown while a page is private is actually a 'feature'.
    However, what's supposed to happen is that the sub-pages inherit the
    permissions of the above page, and private pages that you don't have
    access to aren't even supposed to show up in the link bar. So it's more of
    a 'private pages can't show up in the link bar'.

     
  • Justin Haygood

    Justin Haygood - 2005-07-14

    Logged In: YES
    user_id=937892

    It's still a security vulnerability that it can be seen in
    the first place, and as such, needs fixing.

     

Log in to post a comment.