FriendsOfShopware / FroshPlatformAdminer

Adminer plugin for Shopware Platform
MIT License
10 stars 8 forks source link

/bundles/froshplatformadminer/Adminer/Adminer.php is accessible to non-authenticated users. #2

Closed timruether closed 4 years ago

timruether commented 4 years ago

As adminer is a continuous standard vector for attacks. Please add a check if Shopware backend session user is active.

/bundles/froshplatformadminer/Adminer/Adminer.php is accessible to non-authenticated users.

Chers

Tim

hlohaus commented 4 years ago

see #5