As designed Attachment previews bypass permission

vbresults

Well-known member
Affected version
2.3.2
Attachments to XFRM resources bypass the "Can View Resource Images" permission and show a preview of attachments that users shouldn't have the ability to view in any form.
 
Worling ad designed, all atrachment preview images csn be viewed without any permission checks if the URL is known
 
Back
Top Bottom