Bugs

Delete of attachments doesn't require authentication

I found all of my attachments gone on my site after a day or so's crawl by google.

 

With some testing I found that it doesn't care if you are logged in or not, anyone can delete any attachment.

 

I also notice that all of the images on the mojomojo.org site seem to be missing :-/

Submitted by Unsubscribed User
3 comments

Voting

0 votes