Download & Extend

anon users can view and alter other RSVPs

Project:RSVP
Version:6.x-1.x-dev
Component:Code
Category:bug report
Priority:critical
Assigned:ulf1
Status:closed (fixed)

Issue Summary

Anon users have access to a list of all RSVPs sent out (shown at the bottom of an event) and can RSVP on behalf of others.

Look at: http://dowsett.ca/2008/poker

There are "View Invitation" links at the bottom...

Comments

#1

Thanks for reporting.

It happens if you add at least one email addresses as invitee instead of an existing user name. I will add a fix asap later today or tomorrow.

Thanks,
Ulf

#2

Priority:normal» critical
Assigned to:Anonymous» ulf1

#3

Status:active» fixed

#4

confirmed - it seems to be fixed....and yeah, that one was critical! :)

#5

Status:fixed» closed (fixed)

Automatically closed -- issue fixed for two weeks with no activity.