| Joomla standard RSS feeds leaks email addresses |  |  |  |
| Written by Administrator |
| Saturday, 07 July 2007 09:54 |
Joomla is a fantastic open source content management system, but a recent flaw in 1.5 has come to light to the DSS team.
If you have a joomla site and use the RSS feeds, the feed will by default list your author's emails. Not just their nick, but the actual email address they have used to sign up with.
This is no use - most sites go to great lengths to protect their users emails from spam and unknowingly a well intentioned site could be leaking email information to spam harvesters.
A semi-fix to this, is to set the news feed email to "site" instead of its default "author" in the global configuration administrator menu.
This stops author emails being added to the feeds but still DOES place the site email on every RSS artive feed. This is not great from a site spam point of view. It would be better to prevent any email leakage!
Howver, this is a minor flaw once known about and corrected. |
| Last Updated on Wednesday, 21 July 2010 08:34 |