Closed ScriptKiddy99 closed 5 years ago
With some small manipulation you are able to delete database entries without entering a valid "Secret", this needs looking into, or else someone could wipe the whole DB/Enter more malicious code :)
Can you email me the method to delete items or run malicious code? My email is is on my github account.
Sorry never got the notification for the response! see your email :)
Thanks, this has been fixed
With some small manipulation you are able to delete database entries without entering a valid "Secret", this needs looking into, or else someone could wipe the whole DB/Enter more malicious code :)