Details
-
Bug
-
Resolution: Fixed
-
Medium
-
3.8.7, 3.9.1, 3.9.1rc1
-
None
-
Operating System: Linux
PHP Version: 4.4.4
Database and version: 5.0.20a
Browser (and version): Konqueror
Description
When you're logged in the admin interface, it's possible to enter a url which will create a new class.
Steps to reproduce
If you log in to the admin interface and just enter a bogus url like:
/class/edit/bogus/(language)/eng-GB
You'll automatically create a new class.
This class will also be lost in the database, since it's no information related to any classgroup (In the table ezcontentclass_classgroup, you'll get group_id = 0 and a emty string in group_name).
Solution: Check post variables before any contentclass should be created.