• Hi, I realized that only the generation of the output csv form has security check, in PDb_List_Admin.class.php:

    if (current_user_can(Participants_Db::$plugin_options['plugin_admin_capability']))
      self::_print_export_form();

    The problem is that the post action doesn’t, so someone could copy the export form, and post that action to a website using the plugin. As a possible solution, one could protect the post action with the plugin_admin_capability, on participants-database.php:

    case 'output CSV':
            //this line of code.
            if (!current_user_can(Participants_Db::$plugin_options['plugin_admin_capability'])) die();
            $header_row = array();
            //...

    Could you include this (or something similar) for future updates? Thanks a lot.
    https://wordpress.org/plugins/participants-database/

Viewing 1 replies (of 1 total)
  • Plugin Author Roland Barker

    (@xnau)

    Thanks for that, I hadn’t considered that this would be possible, but I do want to do what I can to make the plugin secure.

Viewing 1 replies (of 1 total)

The topic ‘Output CSV security issue’ is closed to new replies.