We build. You grow.

Get best community software here

Start a social network, a fan-site, an education project with oxwall - free opensource community software

BIG TROUBLE WITH SECURITY | Forum

D
D Oct 10 '13
I have installed Oxwall Platform version 1.5.3 (build 6341) onto my site (You'll understand why I am hesitant to link it), and have set it up with a team of technically competent associates.


All was well until it was brought to my attention that a bug exists where any regular user can edit any blog or post at will with a very easy trick a 6 year old could do.


Obviously I am not going to explain how this works, but needless to say this bug needs to be squashed before I can launch my site. 


I have searched google for hours and combed through 30 pages of forums here and found nothing. Please help!

D
D Oct 10 '13
The issues seems to be patched at wallfm sites and at this site. Obviously someone knows about this.



D
D Oct 10 '13
If anyone could link me to a pre-existing topic(i am still looking for one to no avail) or might be aware of some rookie mistake I am making that might cause such an issue, please shoot me a PM. This really needs to be resolved by tomorrow :(
Dr Saiyas
Dr Saiyas Oct 10 '13
I'm having the same issue with my website. I can't launch my website if any user can mess with the content of the other users. I want people to be able to create their own content, but what's the point if others can destroy it so easily?
fbkca
fbkca Oct 10 '13
Does this only affect the blog plugin?
Dr Saiyas
Dr Saiyas Oct 10 '13
It also affects forum posts.
Alia Team
Alia Oct 11 '13
We are aware of the issue with "Blogs". It will be fixed shortly.
You will get an update plugin notice for "Blogs" once fix is completed.
Alia Team
Alia Oct 11 '13
Dr Saiyas,

Can you PM me how I can reproduce this issue for forum topics?
fbkca
fbkca Oct 11 '13
Ok good. I don't use either :)
Alia Team
Alia Oct 14 '13
"Blogs" plugin was updated 10 mins ago.