YAWIK icon indicating copy to clipboard operation
YAWIK copied to clipboard

XML export reveals non-public information

Open utrenkner opened this issue 9 years ago • 0 comments

Looking at https://yawik.org/demo/en/export/xml, I can see that the YAWIK Demo User is registered with the address [email protected] (in this special case, I can even request a reset of password; the reset finally fails but I am logged in anyway).

In any case: The user's e-mail addresses should surely not be made public! Please review, which data fields can/should be exported and which ones need to remain private.

utrenkner avatar Dec 12 '16 14:12 utrenkner