Fixed Any admin can get list of installed Add-ons via file health check

Kirby

Well-known member
Affected version
2.2.10
Performing and viewing file health check results via Tools controller is not restricted by any admin permission.
This effectively allows any admin to get a list of installed Add-ons by running a file health check.

As this might be sensitive information, accessing this feature should be restricted to admins with permission Upgrade XenForo or Manage Add-ons.
 

XF Bug Bot

XenForo bug fixer bot
Staff member
Thank you for reporting this issue, it has now been resolved. We are aiming to include any changes that have been made in a future XF release (2.2.11).

Change log:
Check for "Manage add-ons" permission when viewing or triggering a file health check
There may be a delay before changes are rolled out to the XenForo Community.
 
Top