Menu

#32 [CMFVisualEditor 0.2] : dtml-tree security problem

open
nobody
None
5
2003-08-13
2003-08-13
No

In editor_browse_files.html.dtml and
editor_browse_images.html.dtml, there are a "dtml-tree"
call.

When members try to browse files or images, there is an
access error, because members are not allowed to browse
all the site objects.

Adding "skip_unauthorized=1" in dtml-tree attributes
corrects this problem.

Discussion

MongoDB Logo MongoDB