Ticket #5535 (closed defect (bug): fixed)

Opened 4 years ago

Last modified 4 years ago

Limit post_password exposure in XML-RPC metaWeblog.getRecentPosts

Reported by: josephscott Owned by: anonymous
Priority: normal Milestone: 2.3.2
Component: XML-RPC Version: 2.3.2
Severity: normal Keywords: has-patch
Cc: josephscott

Description

Add checks to metaWeblog.getRecentPosts so that only users who can edit a post will be provided a post_password, if one is set.

Attachments

xmlrpc.php.diff Download (589 bytes) - added by josephscott 4 years ago.

Change History

comment:1   ryan4 years ago

  • Status changed from new to closed
  • Resolution set to fixed

(In [6496]) Limit post_password exposure. Props josephscott for the patch and xknown for the find. fixes #5535 for 2.4

comment:2   ryan4 years ago

(In [6497]) Limit post_password exposure. Props josephscott for the patch and xknown for the find. fixes #5535 for 2.3

comment:3   ryan4 years ago

  • Milestone changed from 2.4 to 2.3.2
Note: See TracTickets for help on using tickets.