Some of my members discovered an exploit of this mod which allows anyone to find and access all channels, regardless of the permission settings. This is because all the buttons do is:
javascript:display_channel(1);
There are no additional permissions checks and anyone can access our staff chat. All private communication in such channels are in the open.
So all a user has to do is type 'javascript:void(display_channel(1));' in the browser and replace the number 1 by another number, and they are in another channel.
I am still on 2.4.2 though. Has this been fixed in the latest version?
|