cgerling / booktionator

Your custom book trade platform
https://booktionator.firebaseapp.com/
MIT License
1 stars 0 forks source link

Vulnerabilities in Firebase Database Rules #62

Closed omer88 closed 6 years ago

omer88 commented 6 years ago

As evident from this report there is a security issue with the current Firebase Database Rules:

Attackers can manipulate the author under /books/$book_id/offers/$offer_id because of write permission under /books/$book_id.