Security leak in Notes v4.x

OK, Notes r4 and the latest versions are good. But they have a security leak.

Are you a curious person? You will be satisfied. In any database where you have at least Reader access, you can now read ALL the documents you see on the screen. This is interesting especially for those documents OR PARTS of documents HIDDEN in sections or fields.

How? Click on the document in the view, then on the right button of the mouse and choose "Document Properties" from the little gray pop-up or the "Properties" smarticon.

This opens the "Properties for Document" window. Choose the "Fields" tab. There is a list with all the data in the document. OK, is not so easy to read, but the fields names are suggestive (programmers are also humans... maybe) and a lot of interesting data is revealed. From salary to obscene comments.

It works? Have fun!

Back to main page