plainblack.com
Username Password
search
Bookmark and Share

Security: Failure to check privileges in Asset Manager search

User: perlDreamer
Date: 11/25/2009 11:17 am
Views: 982
Rating: 0    Rate [
|
]

A problem was found in the Search screen of the Asset Manager that affects all versions of WebGUI from 7.5 up through WebGUI 7.7.26 and 7.8.5.  A Registered User can use the Delete, Cut and Copy actions in the Search screen to put content into the Trash, or the Clipboard, that they do not normally have privileges for.  This was reported in bug #11272.

http://www.webgui.org/use/bugs/tracker/11272

The problem was fixed in WebGUI 7.7.27 (stable) and WebGUI 7.8.6 (beta).  Patches have been uploaded to the bug for versions 7.6 and 7.5.

We recommend that you take immediate action to protect yourself from this defect.

PreviousBackNext
© 2012 Plain Black Corporation | All Rights Reserved