| |||
|
A security issue has been reported in Gallery, which can be exploited by malicious users to bypass certain security restrictions. The security issue is caused due to incorrect use of the global "$name" variable to determine the gallery name in "classes/postnuke0.7.1/User.php". This can be exploited by PostNuke users with any admin privilege levels to gain access to other user's albums. Solution: The problem has been fixed in version 1.5.1-RC2 |
![]() |
| Tags |
| gallery, integration, issue, postnuke, security |
| Thread Tools | Search this Thread |
| Display Modes | |
|
|
Similar Threads | ||||
| Thread | Thread Starter | Forum | Replies | Last Post |
| Wordpress User Security Issue | blacknight | Security Notices | 1 | 16-01-07 08:30 AM |