thetrials Posted October 21, 2015 Share Posted October 21, 2015 Just posted this as a Bug but wanted to share as well in-case anyone else has experience with this. On our forum we have sub-forums that are only visible to specific user groups and protected by a Password. However, we just discovered that regular users who do not have rights to the forum are able to see the names of topics created in the forum when they click on a users profile. Specifically this shows under currently in a users profile. This has proven to be a security vulnerability for our forum since it means users can see topic names from a protected forum. See included screenshot. The topic next to Currently: is in a protected forum and this is viewable my a regular member. Note that it seems this also affects the online users list as well. Link to comment Share on other sites More sharing options...
Recommended Posts
Archived
This topic is now archived and is closed to further replies.