forked from MarseyWorld/MarseyWorld
Snakes
12d7cfaa6c
Yes, it has been possible for any user to edit any post on the site, their own or otherwise. Only have to generate the POST /edit_post/ manually: an example exploit was created and tested successfully prior to patching. However, abuse of this vulnerability would have generated edit_post modlog entries, the lack of which on prod suggest it was not abused that we know of -- Lord knows how. |
||
---|---|---|
.. | ||
__init__.py | ||
admin.py | ||
awards.py | ||
chat.py | ||
comments.py | ||
discord.py | ||
errors.py | ||
feeds.py | ||
front.py | ||
giphy.py | ||
login.py | ||
lottery.py | ||
notifications.py | ||
oauth.py | ||
polls.py | ||
posts.py | ||
reporting.py | ||
search.py | ||
settings.py | ||
static.py | ||
subs.py | ||
users.py | ||
votes.py |