[wp-trac] [WordPress Trac] #5848: Any registered user can upload files in async-upload.php

WordPress Trac wp-trac at lists.automattic.com
Wed Feb 13 23:10:57 GMT 2008


#5848: Any registered user can upload files in async-upload.php
----------------------+-----------------------------------------------------
 Reporter:  xknown    |       Owner:  anonymous
     Type:  defect    |      Status:  new      
 Priority:  normal    |   Milestone:  2.5      
Component:  Security  |     Version:  2.5      
 Severity:  normal    |    Keywords:           
----------------------+-----------------------------------------------------
 There isn't capability checks in async-upload.php, so any registered user
 is able to upload files.

-- 
Ticket URL: <http://trac.wordpress.org/ticket/5848>
WordPress Trac <http://trac.wordpress.org/>
WordPress blogging software


More information about the wp-trac mailing list