sms_sendtophone_page() checks if the user has set a number but does not check if the number has been confirmed. Thus, users effectively have the 'send to any number' permission. This should be fixed. I've prepared a patch. This patch also includes my trivial fixes from #555922: Unreachable code: "You need need to setup your mobile phone to send messages" and #556002: Typo: repetition of "need" in sms_sendtophone_page().
| Comment | File | Size | Author |
|---|---|---|---|
| sms_sendtophone_page_fixes.patch | 1.38 KB | jpmckinney |
Comments
Comment #1
alone boy commentedfine
Comment #2
univate commentedThis fix committed.