Output CSV security issue
-
Hi, I realized that only the generation of the output csv form has security check, in PDb_List_Admin.class.php:
if (current_user_can(Participants_Db::$plugin_options['plugin_admin_capability'])) self::_print_export_form();The problem is that the post action doesn’t, so someone could copy the export form, and post that action to a website using the plugin. As a possible solution, one could protect the post action with the plugin_admin_capability, on participants-database.php:
case 'output CSV': //this line of code. if (!current_user_can(Participants_Db::$plugin_options['plugin_admin_capability'])) die(); $header_row = array(); //...Could you include this (or something similar) for future updates? Thanks a lot.
https://wordpress.org/plugins/participants-database/
Viewing 1 replies (of 1 total)
Viewing 1 replies (of 1 total)
The topic ‘Output CSV security issue’ is closed to new replies.