uniphil / hes-vendor-dash-issues

0 stars 0 forks source link

it might be possible to spoof the vendor id #28

Closed uniphil closed 3 years ago

uniphil commented 3 years ago

and edit forms for other users

check vendor.php line ~1136 update() and also __construct, which seems like it might get the id from the submitted form.

uniphil commented 3 years ago

marking as low priority because this isn't a generally-public form... hopefully vendors don't try to mess with other vendors!

uniphil commented 3 years ago

fixed