Uploaded custom avatars enumerable and downloadable w/o login despite "Require Sign In View" being set #718
Labels
topic/security
Something leaks user information or is otherwise vulnerable. Should be fixed!
type/bug
Milestone
[x]
):Description
Uploaded custom avatars remain enumerable by their numerical index without having to log in despite the setting "require sign in view" being set. This leaks information about local users (reverse image search, "real" profile pictures, etc) which is probably not intended. I suggest to require a login in this situtation.
Use as:
The text was updated successfully, but these errors were encountered: