View Single Post
bergie's Avatar
Posts: 381 | Thanked: 847 times | Joined on Jan 2007 @ Helsinki
#22
Originally Posted by qole View Post
That is very interesting and disturbing... Someone made it into a page of spam links. There's a security hole in Midgard, methinks.
That area used to be publicly editable, and so I assume some leftover permission set there. So not really a security hole, just setting put there by site admins.

Edit: checked the editing page, and anon users correctly get Access denied: You need the privilege midgard:update. Maybe somebody already changed the permissions of that area

Last edited by bergie; 2009-10-08 at 11:59.