gmapfp

Site officiel du Composant GMapFP Google Map pour Joomla

  • Increase font size
  • Default font size
  • Decrease font size

Which Version ?

Have you a link ?

 GMapFP Forum :: Problèmes de sécurité
Welcome Guest   
Post Reply
 Subject :Re:JCE security leak.. 01-03-2012 17:29:07 
Guest

Guest

The bug seems to be fixed with the new JCE version.

IP Logged
Quote
 Subject :Re:JCE security leak.. 31-12-2011 11:05:26 
gmapfp
Moderator
Joined: 10-06-2009 11:43:41
Posts: 1,833
Location: France

Hi,

What is the function of "JCE" that dangerous ?

You can choose to use "TinyMCE" for default users editor and JCE for specific users ?

IP Logged
Fabrice4821
Quote
 Subject :Re:JCE security leak.. 26-12-2011 11:59:43 
Guest

Guest

Thank you for your reply.

Of course, I checked the "Permissions" pane. With that I found out, that it is the "administrator" right and not the e.g. "registered user" right. I cancelled all permissions but the administrators permission in JCE and it still entered the backend. Then I cancelled the administrators permissions in JCE and this affected the JCE behaviour of the form view in the frontend.

IP Logged
Quote
 Subject :Re:JCE security leak.. 24-12-2011 14:37:17 
gmapfp
Moderator
Joined: 10-06-2009 11:43:41
Posts: 1,833
Location: France

Hi,

Have you look at on the pane "Permissions" of JCE's "Options" ?

IP Logged
Fabrice4821
Quote
 Subject :JCE security leak.. 19-12-2011 23:24:00 
Guest

Guest

First: Thank you for this great component!

I'm using JCE in my website. I put the form to submit a place at the frontend to give every (unregistered) user the opportunity to submit places. I knew, that there could be missuse because of a missing captcha. But I thought it is save, because I have to publish the entries first.

Now I found out, that even guests have administrator rights in the "description" and "opening time and prices" view. Surprised

That is the reason why the JCE displays all Information of my site-backend to everybody. I tried to change the rights of administrators in the JCE options. With that I fixed the leak, but now administrators can't use the full functionality of JCE.

IP Logged
Quote
Post Reply
Page # 


Powered by ccBoard


Thanks for your donation.
Merci pour vos dons.

Module : 1 place at random

My village

Module carte



Who's on line ?

We have 21 guests online

La référence Française pour mettre en valeur vos Lieux Touristique

Ajouter notre Publicité sur votre site