[Security] Reading staff conversation as non admin.
Hi! It looks like you have an issue with authorization using "comments/quote" rest method. As for now it allows non-admin users to get any comment message content (even from non-public staff/mod-talk/ sub-forum) by id. For example message …
Hi!
It looks like you have an issue with authorization using "comments/quote" rest method.
As for now it allows non-admin users to get any comment message content (even from non-public staff/mod-talk/ sub-forum) by id.
For example message with id 46 clearly contains some sensitive admin data about ".. a playful, slightly Hearthstoney font."
Also members page for admin user (like /members/fluxflashor) allows to see the names of threads from staff/ sub-forum, that can also potentially leaks some sensitive information.