You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
If you login as a non-admin webmin site use and use filemin, when you log in as a different user (e.g. root), it tries to load the previous path opened in filemin when you open it (I assume set via cookie which isn't cleared on logout?), but returns an error as it can't find it, disclosing the path the last user was looking at.
I realise this isn't a big deal as it requires two different users to be using the same PC and browser, however as I frequently flick between the admin account and site user accounts, I've noticed it and I thought I'd better bring it up in case it is just part of a bigger issue.
The text was updated successfully, but these errors were encountered:
iliajie
changed the title
Filemin path information disclosure between sessions/users
File Manager: Tabs information should be user-specific between sessions
Jun 7, 2016
If you login as a non-admin webmin site use and use filemin, when you log in as a different user (e.g. root), it tries to load the previous path opened in filemin when you open it (I assume set via cookie which isn't cleared on logout?), but returns an error as it can't find it, disclosing the path the last user was looking at.
I realise this isn't a big deal as it requires two different users to be using the same PC and browser, however as I frequently flick between the admin account and site user accounts, I've noticed it and I thought I'd better bring it up in case it is just part of a bigger issue.
The text was updated successfully, but these errors were encountered: