I noticed that a non registered user can download files without having to log in once he knows the link location, or knows the site uses the Ionfiles component.
Simply by entering the link in his browser:
yourwebsiteURL/download.html?func=download&fileid=1
This is a major security issue.
Noone has experienced this problem ? I see a lot of topic views but no comments.
There are currently 1 users browsing this thread. (0 members and 1 guests)
Bookmarks