View Issue Details
ID | Project | Category | View Status | Date Submitted | Last Update |
---|---|---|---|---|---|
0019426 | phpList 3 application | Admin Management | public | 20-09-18 13:10 | 01-10-18 10:34 |
Reporter | suela | Assigned To | |||
Priority | normal | Severity | minor | Reproducibility | always |
Status | resolved | Resolution | open | ||
Product Version | 3.3.4 | ||||
Target Version | 3.3.5 | ||||
Summary | 0019426: prevent subscriber preferences view/update using only the email | ||||
Description | Currently the URL sending the personal location via email when you choose to update your preferences can be modified changing the "&UID" part of the URL to "&email" making it possible to update other people preferences. | ||||
Tags | No tags attached. | ||||