[MojoMojo] Please upgrade to MojoMojo 1.01

Mateu X. Hunter hunter at missoula.org
Fri May 28 00:42:32 GMT 2010


It's worth noting this only affects sites with open registration.   In that
case, a general authenticated user had permissions to delete any page
(except root node).  We've now completely restricted the delete a page
functionality to 'admin' level users only.


On Thu, May 27, 2010 at 8:11 PM, Dan Dascalescu <ddascalescu at gmail.com>wrot=
e:

> A security issue has been found in MojoMojo versions 1.00 and prior
> whereby an attacker can delete pages they should not have permissions
> to delete.
>
> Users who have open registration enabled are strongly encouraged to
> upgrade to 1.01.
>
> --
> Dan Dascalescu
> http://wiki.dandascalescu.com
>
> _______________________________________________
> Mojomojo mailing list
> Mojomojo at lists.scsys.co.uk
> http://lists.scsys.co.uk/cgi-bin/mailman/listinfo/mojomojo
>
-------------- next part --------------
An HTML attachment was scrubbed...
URL: http://lists.scsys.co.uk/pipermail/mojomojo/attachments/20100527/19ac6=
6cb/attachment.htm


More information about the Mojomojo mailing list