Fixed Inline moderation loophole: Moderators can move posts to threads they can't access

Kirby

Well-known member
Affected version
2.2.7 PL 1
A moderator that only has permissions
  • Use inline moderation on threads / posts
  • Manage (move, merge, etc.) any thread
can move posts from a normally visible thread to a deleted or moderated thread, effectively removing them from public view.

This doesn't seem like smth. that would be expected, especially as merging a normal and a deleted thread does not work.
 
Thank you for reporting this issue, it has now been resolved. We are aiming to include any changes that have been made in a future XF release (2.2.8).

Change log:
Prevent posts from being moved or copied to threads that a moderator cannot view
There may be a delay before changes are rolled out to the XenForo Community.
 
Back
Top Bottom