Notice

The forum is in read only mode.

Support Forum

Welcome! Support Forums have been reactivated
Welcome the Technical Support section. Help us in assisting you by providing us with a concise and descriptive elaboration of your issues. Be specific and if possible, provide us with a step-by-step instruction in replicating your problem.

Security Hole in JomSocial

10 years 3 months ago
  • Mar's Avatar
    Topic Author
  • Mar
  • Offline
  • Fresh Boarder
  • Posts: 64
  • Thank you received: 1
Licenses:
JomSocial Expired

In the early stage of testing we have just found a security hole in Jomsocial.

Due to the sensitive issue of this security we put the description in the hidden panel below.

We appreciate if you could look into this issue urgently.

10 years 3 months ago
  • Chris's Avatar
  • Chris
  • Visitor
  • Thank you received: 0
Licenses:

HI there.

Are you using our latest 3.1.0.4 version? Some of secruity issues were fixed in our latest version.

10 years 3 months ago
  • Mar's Avatar
    Topic Author
  • Mar
  • Offline
  • Fresh Boarder
  • Posts: 64
  • Thank you received: 1
Licenses:
JomSocial Expired

if you have checked the admin console, you should see that I am already at the latest version of jomsocial. This security hole is still present.

10 years 3 months ago
  • Chris's Avatar
  • Chris
  • Visitor
  • Thank you received: 0
Licenses:

Hm...I'll ask our developers about this, all secruity holes should be already fixed in latest release.

10 years 3 months ago
  • Chris's Avatar
  • Chris
  • Visitor
  • Thank you received: 0
Licenses:

M Chabbani, to be honest i tried to follow your steps from description, but it's not very detailed, could you maybe elaborate how we can replicate this issue?

10 years 3 months ago
  • Mar's Avatar
    Topic Author
  • Mar
  • Offline
  • Fresh Boarder
  • Posts: 64
  • Thank you received: 1
Licenses:
JomSocial Expired

thanks. I await your support.

10 years 3 months ago
  • Mar's Avatar
    Topic Author
  • Mar
  • Offline
  • Fresh Boarder
  • Posts: 64
  • Thank you received: 1
Licenses:
JomSocial Expired

Chris, even after your feedback in other thread to close all modules to registered, this security hole is still present. after clicking on photo
anyone can hack into superuser. This issue is quite serious in JomSocial.

Could you please provide solution on this - or at least provide SQL to remove this empty entry in the DB of the empty photo perhaps?

thanks for your support.

10 years 3 months ago
  • Chris's Avatar
  • Chris
  • Visitor
  • Thank you received: 0
Licenses:

Hi there.

I really understand this's a important matter, this's why I need some detailed steps to replicate this problem, I tried following those from misc info and sadly I wasn't able to reproduce this problem. Could you maybe provide us with some more details? Screenshots of the problem? Video maybe?

10 years 3 months ago
  • Paul's Avatar
  • Paul
  • Visitor
  • Thank you received: 0
Licenses:

Hello M Chabbani,

We have tested the process you describe in your first post and if i have accessed my administrator section of the site then not logged off your process to replicate can be achieved, This is due to the browser session remaining open not because of a security hole.

Please do the following to confirm
1. close all your open browsers so that all browser sessions are closed then log into administrator then explicitly log out (don't just close the tab)
2. Follow the process you explained in your first post
3 when you click on the profile link then add /administrator to the URL you will be taken to the administrator login screen

This is a correct process and we are unable to find any security issue

10 years 3 months ago
  • Mar's Avatar
    Topic Author
  • Mar
  • Offline
  • Fresh Boarder
  • Posts: 64
  • Thank you received: 1
Licenses:
JomSocial Expired

Thanks Paul. Indeed it was a cache issue. We will have to constantly remind ourselves during heavy changes at this stage will clear the cache every time. thanks agin.

Moderators: Piotr Garasiński
Powered by Kunena Forum

Join 180,000 websites creating Amazing communities

JomSocial is the most complete, easy-to-use addon that turns Joomla CMS into a
full -fledged, social networking site

TRY NOW BUY NOW