Bug #1077

Post key not checked for attachment management

Added by zinga burga over 1 year ago. Updated over 1 year ago.

Status:Closed Start date:07/11/2010
Priority:Normal Due date:
Assignee:Huji Lee % Done:

100%

Category:Attachments
Target version:1.4.14
Reproducibility:Always Database Type:
Reported In MyBB Version:1.4.13 Database Version:
PHP Version: SQA assignments:
Browser:

Description

Post keys in editpost/newreply/newthread are checked after the attachment management code is run (upload/remove attachment). For editpost, could allow unauthorised adding/removing of attachments.

Associated revisions

Revision 5087
Added by Huji Lee over 1 year ago

Fixes Post key not checked for attachment management (fixes:1077)

History

Updated by Huji Lee over 1 year ago

  • Status changed from New to Assigned
  • Assignee set to Huji Lee
  • Target version set to 1.4.14

Due to its importance in terms of security, I'm fixing it in 1.4 branch as well.

Updated by Huji Lee over 1 year ago

  • Status changed from Assigned to Resolved
  • % Done changed from 0 to 100

Applied in changeset r5087.

Updated by Stefan T. over 1 year ago

  • Status changed from Resolved to Closed
  • Reproducibility changed from Often to Always

Also available in: Atom PDF