Overriding start/stop dates not checked

Bug #746182 reported by Richard Mansfield on 2011-03-31
258
This bug affects 1 person
Affects Status Importance Assigned to Milestone
Mahara
High
Richard Mansfield
1.0
High
Unassigned
1.2
High
Richard Mansfield
1.3
High
Richard Mansfield

Bug Description

Bug #722475 suggests that the view start/stop date overrides are more restrictive than they should be, but having checked that bug it seems they're not checked at all.

CVE References

Changed in mahara:
assignee: nobody → Richard Mansfield (richard-mansfield)
milestone: 1.3.6 → 1.2.9
milestone: 1.2.9 → none
Changed in mahara:
status: In Progress → Confirmed
assignee: Richard Mansfield (richard-mansfield) → nobody
François Marier (fmarier) wrote :

This guy is suggesting that it does work but that the values are changed:

  http://mahara.org/interaction/forum/topic.php?id=3329#post14382

Attaching 1.3 patch to comply with http://wiki.mahara.org/Developer_Area/Security_Team

1.2 patch

Changed in mahara:
status: Confirmed → In Progress
milestone: none → 1.4.0
Changed in mahara:
assignee: nobody → Richard Mansfield (richard-mansfield)
status: In Progress → Fix Committed
visibility: private → public
Changed in mahara:
status: Fix Committed → Fix Released
To post a comment you must log in.
This report contains Public Security information  Edit
Everyone can see this security related information.

Other bug subscribers