Skip to main content
  Tuesday, April 25, 2017
  4 Replies
  1K Visits
  Subscribe
We are testing version 3.6.4 and there is a serious security problem where a user can access documents in categories that he shouldnt have access. Is this solved in latest version?
D
Hi,

We are currently in 4.0.4 version and we don't have any issue like that reported by our customers and it didn't occurred during our tests.
Of course if any issue like that is found, we provide a fix promptly.

Please update the extensions and open a support ticket so we can check if there is anything related to your site configuration.

Best regards.
E
8 years ago
I havent bought yet the extension, but you can check really fast by creating 2 categories, one with access and one without. Lets say we dont have access to file 29 on category 13. (wp-admin/admin-ajax.php?juwpfisadmin=false&action=wpfd&task=file.download&wpfd_category_id=13&wpfd_file_id=29). If we have access to category 11, we can get the file by issuing a request to wp-admin/admin-ajax.php?juwpfisadmin=false&action=wpfd&task=file.download&wpfd_category_id=11&wpfd_file_id=29 we can get the file because no check is made if the file 29 is actually in category 11. If you can confirm this is fixed, we are ready to buy the product. Thanks
D
Hi,

I just tried and you're right there is something wrong here, we'll provide a fix today or tomorrow.
I've applied a free licence to your current account to thanks you for this information.

Best regards.
E
8 years ago
thanks you, i will test it now, i see its updated
  • Page :
  • 1
There are no replies made for this post yet.