Welcome, Guest
Username: Password: Remember me
  • Page:
  • 1

TOPIC: [SOLVED] 2.7.1 - Serious Security Flaw Remains

[SOLVED] 2.7.1 - Serious Security Flaw Remains 14 years 1 month ago #10319

  • andybon
  • andybon's Avatar Topic Author
  • Offline
  • Gold Boarder
  • Gold Boarder
  • Posts: 239
  • Thank you received: 0
17th Dec Update - This issue remains in 2.7.1 for 'Pay Options' - Someone can get to your system and change for example the PayPal account where all the money is sent!!!!!!

Just to warn everyone - If you are using the front end Event Management screen - Make sure you configure access to it as registered only - if you leave it as the default then a non logged in user and access and play around with / delete all your events!!!!!! :shock:

A ticket has been posted on this and the DTH team are aware of the issue....

Please Log in or Create an account to join the conversation.

Last Edit: by andybon.

2.0.7i - Serious Security Flaw Remains 14 years 4 weeks ago #10395

  • andybon
  • andybon's Avatar Topic Author
  • Offline
  • Gold Boarder
  • Gold Boarder
  • Posts: 239
  • Thank you received: 0
In 2.0.7i this is much improved, but there's still a easy way non-registered users can cause damage....

If they select 'Pay Options' on the Events Control Panel page then they can access, change and delete all the configured pay options!!!!!! :shock:

Please Log in or Create an account to join the conversation.

[SOLVED] 2.7.1 - Serious Security Flaw Remains 14 years 3 weeks ago #10518

  • andybon
  • andybon's Avatar Topic Author
  • Offline
  • Gold Boarder
  • Gold Boarder
  • Posts: 239
  • Thank you received: 0
Dec 17th UPDATE - Confirming this issue REMAINS with the latest version 2.7.1..... :( It's just limited to the 'Pay Options' item on the Events Control Panel - but that's serious enough!!!! :shock:

Support Ticket has been updated too.....

Please Log in or Create an account to join the conversation.

[SOLVED] 2.7.1 - Serious Security Flaw Remains 14 years 2 weeks ago #10628

  • dthadmin
  • dthadmin's Avatar
  • Offline
  • Administrator
  • Administrator
  • Posts: 5470
  • Thank you received: 3
This is fixed in 2.7.1b. Requires a reinstall as the fix is done in the database, not a file. Thanks.

Please Log in or Create an account to join the conversation.

  • Page:
  • 1
Time to create page: 0.103 seconds