Group invite
A visitor without an account could view private content inside a group. They could read posts and information meant only for group members. They could not change or add any content to the group.
- Who could do thisAnyone visiting the site. No login needed.
- Does it apply to youThis applies if a user with the access right to create group invites takes certain uncommon actions.
- Has it been used in attacksNo sign of it.
- How urgentDrupal rates this moderately critical. Include it in your next routine update, within the month.
Tell your developerUpdate Group invite to 2.3.9, 3.0.4 or 4.0.4, whichever branch you are on.
For developers: what the fix changed
The release diff is linked below. No summary of the fix has been written for this one.
config/optional/views.view.my_invitations.yml+225 −215ginvite.module+8 −1src/Controller/InvitationOperations.php+7 −0