Make WordPress Core

Opened 20 years ago

Closed 20 years ago

#559 closed defect (bug)

*Looks* like a user can edit comments he/she shouldn't

Reported by: anonymousbugger's profile anonymousbugger Owned by:
Milestone: Priority: normal
Severity: trivial Version:
Component: Administration Keywords:
Focuses: Cc:

Description

User A and User B have the same user_level
User A get get to the edit page for User B's comments (BAD)
BUT User A cannot actually edit the comment (GOOD)

Note also edit_post_link and edit_comment_link appear when they shouldn't

Change History (3)

#1 @anonymousbugger
20 years ago

  • Patch set to No

#2 @2fargon
20 years ago

User B can edit User A's posts' comments too, in CVS version, dated 31st Jan.

The edit post link appears on index.php , even though B cannot edit A's posts.

#3 @michel v
20 years ago

  • Status changed from new to closed

Fixed in CVS.
Thanks for the hints.

Note: See TracTickets for help on using tickets.