We read every piece of feedback, and take your input very seriously.
To see all available qualifiers, see our documentation.
Anonymous users can delete the user data maintained by an AccessControl.userfolder.UserFolder which may prevent any privileged access.
AccessControl.userfolder.UserFolder
The problem is fixed in version 7.2.
The problem can be fixed by adding data__roles__ = () to AccessControl.userfolder.UserFolder.
data__roles__ = ()
#159
Impact
Anonymous users can delete the user data maintained by an
AccessControl.userfolder.UserFolder
which may prevent any privileged access.Patches
The problem is fixed in version 7.2.
Workarounds
The problem can be fixed by adding
data__roles__ = ()
toAccessControl.userfolder.UserFolder
.References
#159