If you know the node ID of a reservation, you have the ability to navigate to the contract through the URL formula sitename.com/merci/contract/%node-id%. This bug makes private contact information available to any person looking for it.
Think is applies to all versions of MERCI but spotted the issue in 6.x-2.9.
Comments
Comment #1
darrick commentedhttp://drupal.org/cvs?commit=494054