Download & Extend

possible security leak: shows inaccessible content

Project:Recent Blocks
Version:6.x-1.x-dev
Component:Code
Category:bug report
Priority:critical
Assigned:Unassigned
Status:active

Issue Summary

This block does not check to see if the user has permissions to see the content. It shows all content, which could be a security problem if users have sensitive information in the block.

Comments

#1

work-around: only show block for appropriate roles in the block settings.

nobody click here