ctrlcctrlv / infinity

A vichan fork permitting users to create their own boards
Other
318 stars 149 forks source link

Security patch #553

Closed Cipherwraith closed 7 years ago

Cipherwraith commented 7 years ago

This security patch removes unnecessary debug modes and group permission levels that can be used by an attacker for privilege escalation.

czaks commented 7 years ago

The patch breaks this:

https://github.com/vichan-devel/vichan/blob/master/inc/config.php#L1573

And other lines that have "DISABLED". The constant isn't defined, as it's being defined from the array.