Jump to content

سكربت اعطاء الاذونات الاصدار [تحديث أمني مهم] 1.4.1


Sora

Recommended Posts

منورين الموضوع

النسخه ماتغير فيها اي شيء باستثناء اصلاح مشكلة أمنيه بالسكربت

ممكن توضح اكثر

انا شفت الرد لكن مافهمته

#5 Jusonex

You should update the resource immediately, because if a server runs it, it would be very easy to get admin rights. A bad person just has to trigger the event "show_apm".

But it's also easy to fix that security problem: Repeat the condition in line 82 (isObjectInACLGroup) before each ACL change (or at least in case of "set_a").

Link to comment
  • 2 weeks later...

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now
  • Recently Browsing   0 members

    • No registered users viewing this page.
×
×
  • Create New...