Skip to content

/series/add: anonymous user can bypass security checks by using special URL #445

Closed
@php-coder

Description

@php-coder

It turns out that we don't have protection in the Spring Security for URLs like /series/add/country/foo and /series/add/category/foo.

Metadata

Metadata

Assignees

Projects

No projects

Milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions