Get your own customer support community
 

Security issue: Regular user (NOT employee) has full access to admin prefs



I am not an employee of TweetDeck - but while browsing their GS product page I noticed the blue "Edit this product" button in the right-hand column. I clicked to see if I could actually edit TweetDeck's product information. I could. I tested it with an otherwise unnoticable change - a small typo, so as not to interfere with their community operations. Unfortunately, the change stuck, meaning I could edit potentially any of the information on their GS page. This seems like a pretty big security risk to me, especially since I do admin a different page - which I suspect might be related.

I'm happy to give more details if necessary. Feel free to email me, I've shared my email address for this submission.

Walker Adamson
RealNetworks, Inc.
 
sad I’m concerned
Inappropriate?
1 person has this problem

The company thinks this is not a problem.


User_default_medium