this post was submitted on 31 Jul 2023
33 points (97.1% liked)

Lemmy.world Support

3250 readers
14 users here now

Lemmy.world Support

Welcome to the official Lemmy.world Support community! Post your issues or questions about Lemmy.world here.

This community is for issues related to the Lemmy World instance only. For Lemmy software requests or bug reports, please go to the Lemmy github page.

This community is subject to the rules defined here for lemmy.world.

To open a support ticket Static Badge


You can also DM https://lemmy.world/u/lwreport or email [email protected] (PGP Supported) if you need to reach our directly to the admin team.


Follow us for server news ๐Ÿ˜

Outages ๐Ÿ”ฅ

https://status.lemmy.world



founded 2 years ago
MODERATORS
 

Hey everyone! I just had something rather weird and concerning happen. While browsing Lemmy through the default web interface, I clicked on a post link and got the usual server error. I refreshed the page and got the same thing. Then, I refreshed a second time and while the post loaded, I was a bit perplexed as my Lemmy theme was completely different. I thought that was weird, so I decided to go Settings. That's when I realized that the username in the top right corner was not my own. Instead of "Shrinra", it showed "aeharding"! I clicked the link for Settings just to see what would happen, and thankfully, it threw me out of the session entirely. In fact, my actual session was gone and I had to log back in.

A part of me thinks I am crazy. Has anyone else experienced this? If so, it is a known security issue? It is more than a bit concerning to think that someone else may be able to access someone else's session just by navigating to a certain page.

Thanks!

you are viewing a single comment's thread
view the rest of the comments
[โ€“] Blamemeta 5 points 1 year ago (2 children)

Probably has some hard coded creds for dev work, and forgot to remove them.

[โ€“] aeharding 8 points 1 year ago

This is an issue with Lemmy-ui which I have nothing to do with. I probably just won the lottery of being displayed as logged in. ๐Ÿ˜›

[โ€“] kuneho 1 points 1 year ago

or just a placeholder