Security bypass
We are testing version 3.6.4 and there is a serious security problem where a user can access documents in categories that he shouldnt have access. Is this solved in latest version?
D
8 years ago
·
#6535 Hi,
We are currently in 4.0.4 version and we don't have any issue like that reported by our customers and it didn't occurred during our tests.
Of course if any issue like that is found, we provide a fix promptly.
Please update the extensions and open a support ticket so we can check if there is anything related to your site configuration.
Best regards.
We are currently in 4.0.4 version and we don't have any issue like that reported by our customers and it didn't occurred during our tests.
Of course if any issue like that is found, we provide a fix promptly.
Please update the extensions and open a support ticket so we can check if there is anything related to your site configuration.
Best regards.
I havent bought yet the extension, but you can check really fast by creating 2 categories, one with access and one without. Lets say we dont have access to file 29 on category 13. (wp-admin/admin-ajax.php?juwpfisadmin=false&action=wpfd&task=file.download&wpfd_category_id=13&wpfd_file_id=29). If we have access to category 11, we can get the file by issuing a request to wp-admin/admin-ajax.php?juwpfisadmin=false&action=wpfd&task=file.download&wpfd_category_id=11&wpfd_file_id=29 we can get the file because no check is made if the file 29 is actually in category 11. If you can confirm this is fixed, we are ready to buy the product. Thanks
D
8 years ago
·
#6539 Hi,
I just tried and you're right there is something wrong here, we'll provide a fix today or tomorrow.
I've applied a free licence to your current account to thanks you for this information.
Best regards.
I just tried and you're right there is something wrong here, we'll provide a fix today or tomorrow.
I've applied a free licence to your current account to thanks you for this information.
Best regards.
- Page :
- 1
There are no replies made for this post yet.
Please login to post a reply
You will need to be logged in to be able to post a reply. Login using the form on the right or register an account if you are new here. Register Here »