Meta: why am I able to view other members' notices?

Meta: why am I able to view other members' notices?

Meta: why am I able to view other members' notices?
Meta: why am I able to view other members' notices?
2024-09-19 02:35:12
Tags: #Security
Model: General Product  
Hardware Version:
Firmware Version:

So I can see another member's profile, like so:

 

https://community.tp-link.com/en/home/uc/info/1108846

 

I've then merged my notices URL with their user id:

 

https://community.tp-link.com/en/home/uc/notice/1108846

 

And was able to see their notices.

 

That doesn't seem right.

 

It seems that it's also possible to dismiss individual notices for another member.

 

That's pretty bad.

 

Please fix!

  0      
  0      
#1
Options
1 Reply
Re:Meta: why am I able to view other members' notices?
2024-09-20 02:36:15

  @dimaqq 

Hi, Thank you very much for the feedback.

The "Member Profile" is like a name card which is open to the community.

But You are not able to view other members' notices.

When you access https://community.tp-link.com/en/home/uc/notice/1108846(or any user ID, like mine-887426), it always leads to your own notification center. 

Thanks a lot and best regards.

 

 

  0  
  0  
#2
Options