Silverstripe Reports are still accessible even when `canView()` returns false
Moderate severity
GitHub Reviewed
Published
Jul 17, 2024
in
silverstripe/silverstripe-reports
•
Updated Aug 1, 2024
Description
Published to the GitHub Advisory Database
Jul 17, 2024
Reviewed
Jul 17, 2024
Published by the National Vulnerability Database
Jul 17, 2024
Last updated
Aug 1, 2024
Reports can be accessed by their direct URL by any user who has access to view the reports admin section, even if the
canView()
method for that report returnsfalse
.References
References