Making WordPress.org

Opened 4 months ago

Last modified 4 months ago

#7682 new defect (bug)

profiles.wordpress.org is displaying in activity discarded/edited messages leading to information disclosure.

Reported by: clalpis's profile clalpis Owned by:
Milestone: Priority: normal
Component: Profiles Keywords:
Cc:

Description

Discarded information are displayed in the activity of any user profile even the text is not present on the edit itself.
Leading for to disclose online of discarded informations.

Please fix urgently

Possible fix refresh activity on edit... ?

https://profiles.wordpress.org/[profilename]/

Change History (2)

#1 @dd32
4 months ago

I've copied this ticket here from #core61504

I've edited the PII from your profile activity, which is what I assume triggered this ticket.

I agree, when a support forum post is edited, ideally we'd ideally also update the excerpt on profiles activity log.

#2 @clalpis
4 months ago

Thanks

Note: See TracTickets for help on using tickets.