?
avatar PhilETaylor
PhilETaylor
15 Oct 2018

Steps to reproduce the issue

Is this meant to be this way?

"Submitting information requests through the frontend is restricted to authenticated users at this time" and then Privacy Requests can be made for email addresses that are not registered users, even made up users...

Seems strange.

If "Submitting information requests through the frontend is restricted to authenticated users at this time" then surely the email address field should be prefilled with the logged in user, or even removed completely and the logged in users email used?

Security issue forked to private repo https://github.com/joomla/cms-security/issues/281 @joomla/security .

avatar PhilETaylor PhilETaylor - open - 15 Oct 2018
avatar joomla-cms-bot joomla-cms-bot - change - 15 Oct 2018
Labels Added: ?
avatar joomla-cms-bot joomla-cms-bot - labeled - 15 Oct 2018
avatar PhilETaylor PhilETaylor - change - 15 Oct 2018
The description was changed
avatar PhilETaylor PhilETaylor - edited - 15 Oct 2018
avatar PhilETaylor PhilETaylor - change - 15 Oct 2018
The description was changed
avatar PhilETaylor PhilETaylor - edited - 15 Oct 2018
avatar PhilETaylor PhilETaylor - change - 15 Oct 2018
The description was changed
avatar PhilETaylor PhilETaylor - edited - 15 Oct 2018
avatar brianteeman
brianteeman - comment - 15 Oct 2018

See joomla-projects/privacy-framework#225

and such a shame that in the entire alpha, beta and multiple RC releases the @joomla/security team did not test this at all

avatar PhilETaylor
PhilETaylor - comment - 15 Oct 2018

and such a shame that in the entire alpha, beta and multiple RC releases the @joomla/security team did not test this at all

Factually incorrect.

avatar PhilETaylor PhilETaylor - change - 15 Oct 2018
Status New Closed
Closed_Date 0000-00-00 00:00:00 2018-10-15 11:07:40
Closed_By PhilETaylor
avatar PhilETaylor PhilETaylor - close - 15 Oct 2018

Add a Comment

Login with GitHub to post a comment