Jump to content

Users can edit posts after the post has been hidden

Go to solution Solved by Marc Stridgen,

Recommended Posts

There's no check that the user has permission to see the post being edited, so it's possible to edit a post after it has already been hidden.

To reproduce:

  • Post in a topic
  • Start editing that post
  • Moderator hides the post
  • Submit the edit
  • Edit goes through successfully

It's not so bad in that repro, because they must have had it open already, but it's not great if the user constructs the calls manually to both load the current version of the post, and make changes to it.

Link to comment
Share on other sites

  • 3 weeks later...
  • Recently Browsing   0 members

    • No registered users viewing this page.
  • Create New...