barcode icon indicating copy to clipboard operation
barcode copied to clipboard

Barcodes PDFs available without authentication or when plugin is disabled

Open kabassanov opened this issue 2 years ago • 0 comments

Hi, Not sure if it is by choice or simply a bug, but generated PDFs are available through front/send.php even when this plugin is disabled. In addition they are also available without user authentication (in particular for guys trying to exploit https://github.com/pluginsGLPI/barcode/security/advisories/GHSA-2pjh-h828-wcw9 vulnerability)...

kabassanov avatar Jun 08 '22 07:06 kabassanov