Plans page doesn't check artefact type

Bug #618306 reported by Dan Poltawski
6
This bug affects 1 person
Affects Status Importance Assigned to Milestone
Mahara
Fix Released
High
Richard Mansfield

Bug Description

The plans page doesn't check the artefact type, so a user could alter the id field and attempt to add tasks to an image for example by going to the url:

http://mahara/artefact/plans/plan.php?id={id of an non-plan artefact}

Changed in mahara:
status: New → Fix Committed
importance: Undecided → High
assignee: nobody → Richard Mansfield (richard-mansfield)
milestone: none → 1.3.0
Changed in mahara:
status: Fix Committed → Fix Released
To post a comment you must log in.
This report contains Public information  
Everyone can see this information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.