Major security issue during registration process
-
This plugin has a major security issue in registration flow.
The URL directing to final registration confirmation looks like this:
/?action=show_confirm_mess&event_id=1®_id=120It contains reg_id parameter. By manually altering this parameter (for example decrease it), information of other registrations becomes visible.
Viewing 2 replies - 1 through 2 (of 2 total)
Viewing 2 replies - 1 through 2 (of 2 total)
- The topic ‘Major security issue during registration process’ is closed to new replies.