Details
-
Bug
-
Resolution: Fixed
-
Major
-
2.2.1
-
None
-
Easy
-
Description
By claiming to be a different user, a user can post a comment on a page and it will appear to be from a different user.
This can be solved without breaking backward compatibility by disallowing certain words from the author field or escaping characters.