Hello,
Serious issue here - we would be unable to upgrade to V5 with this security hole in existence.
In month view of the calendar (/events/2025/1/, for example) if we hover the cursor over an event then a popup occurs which displays the event detail and a Google Map. Superficially, this appears to be the same as under V4 - so OK, so far - superficially!
But, when I use the browser developer tools to monitor network traffic I get the following "GET https://maps.googleapis.com/maps/api/staticmap?center=Rochester, Kent&size=300x200&markers=Rochester, Kent&key=<our-no-longer-secret-key>&scale=1&maptype=roadmap"
Note - this is the developer tools in the browser - not the Invision server - so any member, guest or hacker can steal our secret key from our V5 site.
Of course, I went into "blind panic mode" worrying that we could have been exposing our secret key under V4 - but luckily this appears to be a new defect under V5 as I could not see our secret key being exposed under V4.
Thanks.
John
Recommended Comments