[wp-trac] Re: [WordPress Trac] #8801: Low privilege user can see email address of comment author by HTML source

WordPress Trac wp-trac at lists.automattic.com
Mon Jan 5 19:39:06 GMT 2009


#8801: Low privilege user can see email address of comment author by HTML source
---------------------------------------------------+------------------------
 Reporter:  lilyfan                                |        Owner:  anonymous
     Type:  defect (bug)                           |       Status:  new      
 Priority:  normal                                 |    Milestone:  2.7.1    
Component:  Administration                         |      Version:  2.7      
 Severity:  critical                               |   Resolution:           
 Keywords:  email comments autor has-patch tested  |  
---------------------------------------------------+------------------------
Changes (by mrmist):

  * keywords:  email comments autor => email comments autor has-patch
               tested

Comment:

 I've attached the same or a similar patch, the other one seemed a bit odd?

 Given it a quick test in IE and Opera, seems ok.  My patch just blanks out
 the fields if user can't edit the relevant post.

-- 
Ticket URL: <http://trac.wordpress.org/ticket/8801#comment:1>
WordPress Trac <http://trac.wordpress.org/>
WordPress blogging software


More information about the wp-trac mailing list