scheideggstrasse 0 Posted October 16, 2022 Posted October 16, 2022 Hello, I didn't find the right forum to post this - it's probably more a bug as a featuere: I came across a potential "data breach" with emby connect. If I add an user on my local emby server and enter the emby connect username, it shows me the mail of the user. For example I added "ramer" and it showed me the mail "ramerbiggs417@gmail.com" - that shouldn't be the case from my point of view. This way I could program a script with "dummy" usernames and get 100s of mails of emby users. Cheers
GrimReaper 4749 Posted October 16, 2022 Posted October 16, 2022 (edited) Actually, linking via Connect usernames should be disbanded altogether and only emails used IMHO. Edited October 16, 2022 by GrimReaper Typo 2
visproduction 316 Posted October 16, 2022 Posted October 16, 2022 (edited) I am not familar with Emby connect. Isn't "Add user" an admin only function. Admin person, in any web social network code, can see user's data and contact. Make the users non-admin. Does that not stop them form being able to add users? Edited October 16, 2022 by visproduction
Spaceboy 2573 Posted October 16, 2022 Posted October 16, 2022 5 minutes ago, visproduction said: I am not familar with Emby connect. Isn't "Add user" an admin only function. Admin person, in any web social network code, can see user's data and contact. Make the users non-admin. Does that not stop them form being able to add users? emby allows adding of user accounts by use of the forum username. so for instance i can see your email address is a @cox.net one 1
ebr 16187 Posted October 18, 2022 Posted October 18, 2022 On 10/16/2022 at 11:10 AM, visproduction said: Isn't "Add user" an admin only function. Yes it is.
ebr 16187 Posted October 18, 2022 Posted October 18, 2022 On 10/16/2022 at 10:46 AM, GrimReaper said: Actually, linking via Connect usernames should be disbanded altogether and only emails used IMHO. That is the plan but we needed a transition. 1
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now