When i go to my inbox (message plugin) the link is someting like
http://www.mydomain.com/messages/inbox/myuserid
when i replace "myuserid" with my "otheruserid" i.e.,
http://www.mydomain.com/messages/inbox/otheruserid
I am able to see his inbox and every other stuff....
Please tell me a way to fix it... i m using elgg 1.8.8...!!!
info@elgg.org
Security issues should be reported to security@elgg.org!
©2014 the Elgg Foundation
Elgg is a registered trademark of Thematic Networks.
Cover image by Raül Utrera is used under Creative Commons license.
Icons by Flaticon and FontAwesome.
- Matt Beckett@Beck24

Matt Beckett - 0 likes
- happy gupta@bornrockstar123

happy gupta - 0 likes
- Matt Beckett@Beck24

Matt Beckett - 0 likes
- happy gupta@bornrockstar123

happy gupta - 0 likes
- iionly@iionly

iionly - 0 likes
- Matt Beckett@Beck24

Matt Beckett - 0 likes
You must log in to post replies.You're an administrator - you can see other peoples stuff. Try it as a non-admin, you won't be able to see any messages - no privacy issue.
yes i created a demo user who is not an admin... that profile can also see the messages...
Then there's something wrong with your installation, or more likely, you're using a plugin that's failing the security. I tested it after you posted, and on a default installation a non-admin cannot see another users messages.
ok ok got it... Admin can see the message but a non-admin will see it with "NO MESSAGE"
its ok... :)
http://trac.elgg.org/ticket/4879
Yes, it's definitely a UI bug. Just not a privacy issue :)