just-kile / Zapfmaster2000

facebook.com/Zapfmaster2000
2 stars 1 forks source link

Draftkitcreation is insecure #167

Open partysalat opened 10 years ago

partysalat commented 10 years ago

If you create a box at dashboard (PUT: rest/draftkit), the token will not be checked if it belongs to an admin or not.