October 21, 2015 in Technical Problems
Just posted this as a Bug but wanted to share as well in-case anyone else has experience with this. On our forum we have sub-forums that are only visible to specific user groups and protected by a Password. However, we just discovered that regular users who do not have rights to the forum are able to see the names of topics created in the forum when they click on a users profile. Specifically this shows under currently in a users profile. This has proven to be a security vulnerability for our forum since it means users can see topic names from a protected forum. See included screenshot. The topic next to Currently: is in a protected forum and this is viewable my a regular member.
Note that it seems this also affects the online users list as well.
This topic is now archived and is closed to further replies.
Started Thursday at 01:08 PM
Started November 17
Started April 13