[SECURITY] Information Disclosure in Wizards
It has been possible for authenticated editors
to show content of arbitrary tables and fields
that are defined in TCA by manipulating
GET parameters of the forms and table wizard.
This change adds a check if the editor has access
to the given record.
Change-Id: I524ae9bd75a5cca9e37918e64f5c492c9fa3c36e
Fixes: #41714
Releases: 4.5, 4.7, 6.0, 6.1, 6.2
Security-Commit:
9ee30833350405d003de206501118d1300998bee
Security-Bulletin: TYPO3-CORE-SA-2013-004
Reviewed-on: https://review.typo3.org/26180
Reviewed-by: Oliver Hader
Tested-by: Oliver Hader