Hello EasyRetro Team,
I would like to report a security issue I encountered on the platform related to comment editing in a board with hidden comments.
Currently, an authenticated user is able to edit another user's comment before it is revealed, exposing its content improperly.
A user should not be able to edit a comment that is not yet visible on the board, ensuring the integrity of the information until it is officially revealed.
Please let me know if you need further details or a step-by-step reproduction of the issue.
I'm happy to assist.
Thank you for your great work!
Best regards,
André Gustavo
Please authenticate to join the conversation.
Rejected
EasyRetro
About 1 year ago

Gustavo Maia
Get notified by email when there are changes.
Rejected
EasyRetro
About 1 year ago

Gustavo Maia
Get notified by email when there are changes.