daniel-nagy / md-data-table

Material Design Data Table for Angular Material
MIT License
1.9k stars 518 forks source link

Live Demo has security breach (Kinda) #657

Closed ScriptKiddy99 closed 5 years ago

ScriptKiddy99 commented 5 years ago

With some small manipulation you are able to delete database entries without entering a valid "Secret", this needs looking into, or else someone could wipe the whole DB/Enter more malicious code :)

daniel-nagy commented 5 years ago

Can you email me the method to delete items or run malicious code? My email is is on my github account.

ScriptKiddy99 commented 5 years ago

Sorry never got the notification for the response! see your email :)

daniel-nagy commented 5 years ago

Thanks, this has been fixed