pluginsGLPI / barcode

GNU Affero General Public License v3.0
36 stars 34 forks source link

Barcodes PDFs available without authentication or when plugin is disabled #99

Open kabassanov opened 2 years ago

kabassanov commented 2 years ago

Hi, Not sure if it is by choice or simply a bug, but generated PDFs are available through front/send.php even when this plugin is disabled. In addition they are also available without user authentication (in particular for guys trying to exploit https://github.com/pluginsGLPI/barcode/security/advisories/GHSA-2pjh-h828-wcw9 vulnerability)...