codekasten/ezmlm-web-ng/ezmlm-web-2.1-ng/TODO.ng

2 lines
121 B
Text
Raw Normal View History

check permission before actions like "change", "create" or "delete" - the command could be arbitrarily injected into GET