We read every piece of feedback, and take your input very seriously.
To see all available qualifiers, see our documentation.
A PATCH request to /guilds/:id/members/:id allows any user regardless of rights to edit any other user's nickname, guild profile bio, or guild avatar.
/guilds/:id/members/:id
This is fixed as of commit 51239d6
Summary
A PATCH request to
/guilds/:id/members/:id
allows any user regardless of rights to edit any other user's nickname, guild profile bio, or guild avatar.Mitigation
This is fixed as of commit 51239d6