Buddypress Activity Feed
Quote from tmcecelia on April 11, 2021, 3:49 amIt appears that the buddypress asgaros integration may have a security issue.
Has anyone noticed that if you have a separate forum category created for moderators but a regular member clicks on that moderators activity feed any of the posts made in the moderator only forum are visible. At least the first few lines. If a member tries to click on it, the warning saying they don’t have permission to access pops up, but several lines of comment are clearly visible to the unauthorized user.
Does anyone have a workaround or patch for this?
Tat
It appears that the buddypress asgaros integration may have a security issue.
Has anyone noticed that if you have a separate forum category created for moderators but a regular member clicks on that moderators activity feed any of the posts made in the moderator only forum are visible. At least the first few lines. If a member tries to click on it, the warning saying they don’t have permission to access pops up, but several lines of comment are clearly visible to the unauthorized user.
Does anyone have a workaround or patch for this?
Tat
Uploaded files:Quote from tmcecelia on April 11, 2021, 4:04 amSorry just read that this is a known issue 😅
Question still stands on if anyone has a workaround that seems to work for them?
Sorry just read that this is a known issue 😅
Question still stands on if anyone has a workaround that seems to work for them?