You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Screenshots that are added to a ticket become publicly available, only limited by the knowledge of a fairly short ID. This is a no-go, IMHO, because screenshots on a helpdesk often contain sensitive data (financials, PII, customers, etc.).
Yes, they are only available under a random ID, but
this does not help when the IDs become known through a different vulnerability
7 characters are not too hard to brute force
Version
frappe: 16.0.0-dev
helpdesk: 1.1.0
Installation method
None
Relevant log output / Stack trace / Full Error Message.
No response
The text was updated successfully, but these errors were encountered:
Information about bug
Screenshots that are added to a ticket become publicly available, only limited by the knowledge of a fairly short ID. This is a no-go, IMHO, because screenshots on a helpdesk often contain sensitive data (financials, PII, customers, etc.).
Yes, they are only available under a random ID, but
Version
frappe: 16.0.0-dev
helpdesk: 1.1.0
Installation method
None
Relevant log output / Stack trace / Full Error Message.
No response
The text was updated successfully, but these errors were encountered: