Quote:
Originally Posted by Piggo
In what version was this added?
Because I was (unfortunately) successfully able to spoof the from-email, and post a message as a different user in my currently installed version (I think 2.1).
This security issue is the main reason I have not gone full scale yet with this mod, as I feared anyone could post as anyone else, providing they knew the other person's email addy.
|
Piggo, I'll let Cyricx answer this more authoritatively -
I'm using this mod to mimic a mailing list, but also have the ability for users to search and post via the forum interface. The spoofing of users is intrinsic of mailing lists, and is something that I am comfortable with, seeing that I moved away form a mailing list - and came from that security level.
With that being said, the same issue exists for Yahoo groups, as someone can post as another user if they know the other users email address.
All in all, I think this plugin adds a great feature set, is well maintained, and is progressing well. Its honestly the major reason we moved from a pure mailing list environment.
-