spree_wishlist icon indicating copy to clipboard operation
spree_wishlist copied to clipboard

WishlistsController has no access control. Allows public editing of everything.

Open mleglise opened this issue 9 years ago • 1 comments

That's right, anonymous users can edit and delete other people's wishlists, just by having the right URL. No permission checks are performed.

mleglise avatar Sep 15 '15 21:09 mleglise

I am also facing the same issue. Getting error when I am trying to delete product from the wishlist. Please resolve this ASAP.

Thank you in Advance.

sonu1989 avatar Dec 31 '15 13:12 sonu1989