xiaomlove / nexusphp

A private tracker application base on NexusPHP
https://nexusphp.org
GNU General Public License v2.0
843 stars 175 forks source link

Contents of shoutbox can be accessed without logging in #247

Closed hauntedrows closed 3 months ago

hauntedrows commented 4 months ago

It appears that the shoutbox.php URI is not secured by a check to ensure that the user is logged in.

By editing the URL, any user can bring up the current contents of the tracker's shoutbox in a browser window.

This would appear to be a serious security hole.

xiaomlove commented 4 months ago

Fixed, see here