Requests can be created in the web without web validation being applied.
The DLL is allowing the creation of a new transaction from a GET request. Creating a new record (transaction/user/etc) should only be allowed with POST actions.
1
vote
Genie Shropshire
shared this idea
released
·
AdminDustin Stokes
(Chief Technology Officer @ Atlas Systems, Inc., Atlas Systems, Inc.)
responded
Released in Aeon 4.0