hoplaa opened this issue on Sep 25, 2009 ยท 6 posts
hoplaa posted Fri, 25 September 2009 at 1:29 PM
This is what the personalized link to a newsletter looks like (it's addressed to me):
My email address is displayed at the bottom of that page.
Can you guess what happens if the number between the last pair of forward slashes is changed?
That's right, you get another person's newsletter along with their email address. It would therefore be trivial to harvest all the email addresses of the newsletter subscribers, yes?
I don't think this is a good thing. A simple fix would be to remove the email address from the page.