dmeese / MathWorld

Team Bunny Slippers Math World Web Application
0 stars 1 forks source link

Users_controller: destroy #22

Open mlbriel opened 11 years ago

mlbriel commented 11 years ago

When a user is destroyed, there is no check for and deletion of previously uploaded content. If this data is indexed by the user ID, a vulnerability could be introduced if the stored content is referenced or the content could orphaned resulting in uncollectible garbage.

dmeese commented 11 years ago

I think you're on to something here. I'll look into it.