Files
BookStack/app
Dan Brown e765e61854 Addressed user detail harvesting issue
Altered access & usage of the /search/users/select endpoint with the
following changes:
- Removed searching of email address to prevent email detail discovery
  via hunting via search queries.
- Required the user to be logged in and have permission to manage users
  or manage permissions on items in some way.
- Removed the user migration option on user delete unless they have
  permission to manage users.

For #3108
Reported in https://huntr.dev/bounties/135f2d7d-ab0b-4351-99b9-889efac46fca/
Reported by @haxatron
2021-12-14 18:47:22 +00:00
..
2021-11-14 16:28:01 +00:00
2021-06-26 15:23:15 +00:00
2021-06-26 15:23:15 +00:00
2021-11-04 22:42:35 +00:00
2021-06-26 15:23:15 +00:00
2021-11-06 00:32:01 +00:00
2021-08-21 14:49:40 +00:00
2021-11-06 00:32:01 +00:00
2021-06-26 15:23:15 +00:00
2021-07-03 12:02:13 +01:00
2021-11-06 22:00:33 +00:00