MantisBT: master f779e3d4

Author Committer Branch Timestamp Parent
rombert dregad master 2014-04-30 11:42 master b509ab38
Affected Issues  0017243: CVE-2014-8553: SOAP API: leak of user personal information
Changeset

SOAP API: apply access control to mci_account_get_array_by_id

The access controls are the same as the ones applied by
view_user_page.php, with the single addition of making the info
available if the user requests their own information.

This preserves the behaviour of the mc_login method call.

Fixes 0017243 (leak of user personal information)

Signed-off-by: Damien Regad dregad@mantisbt.org

mod - api/soap/mc_account_api.php Diff File