gruenes-brett / community-calendar

Wordpress plugin that allows users to submit events to a website and to show them in a calendar
GNU General Public License v3.0
1 stars 1 forks source link

Fix unauthorized event modification #35

Closed joergrs closed 2 years ago

joergrs commented 2 years ago

As an author, by modifying the hidden event ID field in the edit event form it is possible to hijack and edit other peoples events.