Summary: Privacy issue: ResourceLoader lets you request other
                    user's preferences
           Product: MediaWiki
           Version: 1.17-svn
          Platform: All
        OS/Version: All
            Status: NEW
          Severity: major
          Priority: Normal
         Component: Resource Loader

With load.php?modules=user.options&user=OtherUser you can easily retrieve
someone else's preferences including the watchlist token.

Needs a check against $wgUser I think.

Configure bugmail:
------- You are receiving this mail because: -------
You are on the CC list for the bug.

Wikibugs-l mailing list

Reply via email to