Approval module security problem - AGAIN!
I would like to inform that again we've found SD (Enterprise 8022 edition) very usecure with use of approval module.
Anyone can build URL link (ITEM and KEY are easy to find) and see the whole request body - download attachments fe - without ANY AUTHORISATION!
I suppose it is the same error or error-scheme found in mid 2010 and confirmed by support.
Lack of support in this case is really hard to tolerate.
Example:
If you've ever received ANY approval link/form (as requester) you can easily build another.
New to ADSelfService Plus?