Home
Community
Download
Customize
Modifications
Themes
Upgrades
Support
Function Database
Online Manual
About
Contribute
Development
Please
login
or
register
.
1 Hour
1 Day
1 Week
1 Month
Forever
Login with username, password and session length
This topic
This board
Entire Site
Community
Modifications
Themes
Online Manual
Mantis
Select language:
Albanian
Arabic
Bulgarian
Catalan
Chinese Simplified
Chinese Traditional
Croatian
Czech Informal
Czech
Danish
Dutch
English British
English
Esperanto
Estonian
Finnish
French
Galician
German Informal
German
Greek
Hebrew
Hungarian
Indonesian
Italian
Japanese
Kurdish Kurmanji
Lithuanian
Macedonian
Malay
Norwegian
Persian
Polish
Portuguese Brazilian
Portuguese Pt
Romanian
Russian
Serbian Cyrillic
Serbian Latin
Slovak
Slovenian
Spanish Es
Spanish Latin
Swedish
Thai
Turkish
Ukrainian
Urdu
Vietnamese
News:
Read the blogs!
Home
Help
Search
Login
Register
Advertisement:
Simple Machines Community Forum
»
SMF Development
»
Bug Reports
»
Fixed or Bogus Bugs
»
Topic:
Any vulnerability found?
« previous
next »
Print
Pages: [
1
]
Go Down
Author
Topic: Any vulnerability found? (Read 2367 times)
musicus
Semi-Newbie
Posts: 94
Gender:
Any vulnerability found?
«
on:
April 11, 2012, 04:38:38 PM »
A user in my forum has alerted me on it. Since it it is possible as a normal user to edit texts by other users. This error occurs, not always, but occasionally it happens that every normal user can manipulate text by other users.
All permissions are set correctly
Sorry my bad english
Logged
--
gruss musicus
http://www.bamdorner.de
http://music-society.net
K@
Lead Support Specialist
SMF Master
Posts: 38,700
Gender:
Nothing (Or nothing you can see)
Re: Any vulnerability found?
«
Reply #1 on:
April 11, 2012, 04:48:59 PM »
The permission you want, isn't shown in either of your screenshots.
The one you want is "Modify posts", left-hand column, second from bottom.
Logged
musicus
Semi-Newbie
Posts: 94
Gender:
Re: Any vulnerability found?
«
Reply #2 on:
April 11, 2012, 04:55:51 PM »
Here is the lost part
Logged
--
gruss musicus
http://www.bamdorner.de
http://music-society.net
K@
Lead Support Specialist
SMF Master
Posts: 38,700
Gender:
Nothing (Or nothing you can see)
Re: Any vulnerability found?
«
Reply #3 on:
April 11, 2012, 05:10:00 PM »
Weird.
This is a long-shot...
Do the members concerned belong in more than one membergroup, because of post-count groups?
Are they inheriting permissions from there?
If not, I'm stumped, I'm afraid.
Logged
musicus
Semi-Newbie
Posts: 94
Gender:
Re: Any vulnerability found?
«
Reply #4 on:
April 11, 2012, 05:24:17 PM »
I have two extra Membergroups
Sponsor - normal Users, but they spend money for the server
Zerro - new users - 0-posters
Logged
--
gruss musicus
http://www.bamdorner.de
http://music-society.net
emanuele
Developer
SMF Super Hero
Posts: 11,884
Gender:
Because Orange is Orange
Re: Any vulnerability found?
«
Reply #5 on:
April 11, 2012, 05:32:19 PM »
(almost) Nothing happen "randomly".
Here there is a pattern and I can see it by the half permission in your second picture: "Modify replies to own topics".
That permission gives the possibility to the member who start the topic to modify all the answers to that topic.
Logged
Checkout how SMF 2.1 is going
Supporto in Italiano?
* emanuele dislikes "like" and alike
The WIKI helps you, help the WIKI!
Il WIKI ti aiuta, aiuta il WIKI!
Aiutateci ad aiutarvi: spiegate bene il vostro problema
: no, "non funziona" non è una spiegazione!!
1) Cosa fai,
2) cosa ti aspetti,
3) cosa ottieni.
musicus
Semi-Newbie
Posts: 94
Gender:
Re: Any vulnerability found?
«
Reply #6 on:
April 11, 2012, 05:36:37 PM »
But this user who has alerted me to the error, belongs to none or groups mentioned above
Logged
--
gruss musicus
http://www.bamdorner.de
http://music-society.net
emanuele
Developer
SMF Super Hero
Posts: 11,884
Gender:
Because Orange is Orange
Re: Any vulnerability found?
«
Reply #7 on:
April 11, 2012, 05:39:41 PM »
My post refers to your very first post and this image:
Logged
Checkout how SMF 2.1 is going
Supporto in Italiano?
* emanuele dislikes "like" and alike
The WIKI helps you, help the WIKI!
Il WIKI ti aiuta, aiuta il WIKI!
Aiutateci ad aiutarvi: spiegate bene il vostro problema
: no, "non funziona" non è una spiegazione!!
1) Cosa fai,
2) cosa ti aspetti,
3) cosa ottieni.
musicus
Semi-Newbie
Posts: 94
Gender:
Re: Any vulnerability found?
«
Reply #8 on:
April 11, 2012, 05:48:18 PM »
Is that better?
Logged
--
gruss musicus
http://www.bamdorner.de
http://music-society.net
emanuele
Developer
SMF Super Hero
Posts: 11,884
Gender:
Because Orange is Orange
Re: Any vulnerability found?
«
Reply #9 on:
April 11, 2012, 05:53:27 PM »
Sorry, but no idea...
I don't speak German.
What I'm saying is that in the image I re-posted there is in the last half line selected the permission "Modify replies to own topics", remove that from any of your groups and the error should disappear.
Logged
Checkout how SMF 2.1 is going
Supporto in Italiano?
* emanuele dislikes "like" and alike
The WIKI helps you, help the WIKI!
Il WIKI ti aiuta, aiuta il WIKI!
Aiutateci ad aiutarvi: spiegate bene il vostro problema
: no, "non funziona" non è una spiegazione!!
1) Cosa fai,
2) cosa ti aspetti,
3) cosa ottieni.
musicus
Semi-Newbie
Posts: 94
Gender:
Re: Any vulnerability found?
«
Reply #10 on:
April 11, 2012, 05:56:53 PM »
sorry, now in english
Logged
--
gruss musicus
http://www.bamdorner.de
http://music-society.net
emanuele
Developer
SMF Super Hero
Posts: 11,884
Gender:
Because Orange is Orange
Re: Any vulnerability found?
«
Reply #11 on:
April 11, 2012, 06:01:23 PM »
The permission I'm telling you to remove is not in that part, is a bit below.
You can simply remove the tick from the permission and save.
Logged
Checkout how SMF 2.1 is going
Supporto in Italiano?
* emanuele dislikes "like" and alike
The WIKI helps you, help the WIKI!
Il WIKI ti aiuta, aiuta il WIKI!
Aiutateci ad aiutarvi: spiegate bene il vostro problema
: no, "non funziona" non è una spiegazione!!
1) Cosa fai,
2) cosa ti aspetti,
3) cosa ottieni.
musicus
Semi-Newbie
Posts: 94
Gender:
Re: Any vulnerability found?
«
Reply #12 on:
April 11, 2012, 06:07:44 PM »
I hope thats right
Logged
--
gruss musicus
http://www.bamdorner.de
http://music-society.net
emanuele
Developer
SMF Super Hero
Posts: 11,884
Gender:
Because Orange is Orange
Re: Any vulnerability found?
«
Reply #13 on:
April 11, 2012, 06:09:30 PM »
Now, if all your groups are set that way (in your first picture it doesn't seem to be the case) you should be fine.
Logged
Checkout how SMF 2.1 is going
Supporto in Italiano?
* emanuele dislikes "like" and alike
The WIKI helps you, help the WIKI!
Il WIKI ti aiuta, aiuta il WIKI!
Aiutateci ad aiutarvi: spiegate bene il vostro problema
: no, "non funziona" non è una spiegazione!!
1) Cosa fai,
2) cosa ti aspetti,
3) cosa ottieni.
musicus
Semi-Newbie
Posts: 94
Gender:
Re: Any vulnerability found?
«
Reply #14 on:
April 11, 2012, 06:11:23 PM »
Thank you for your help
Logged
--
gruss musicus
http://www.bamdorner.de
http://music-society.net
Print
Pages: [
1
]
Go Up
« previous
next »
Simple Machines Community Forum
»
SMF Development
»
Bug Reports
»
Fixed or Bogus Bugs
»
Topic:
Any vulnerability found?