- Posts: 13
- Thank you received: 0
Kunena 7.0.6 & Kunena 6.4.12 – Security Updates Released
The Kunena team has announce the arrival of Kunena 7.0.6 [K 7.0.6] in stable which is now available for download as a native Joomla extension for J! 5.4.x/6.0.x. This version addresses most of the issues that were discovered in K 6.2 / K 6.3 / K 6.4 and issues discovered during the last development stages of K 7.0.
The Kunena team is also pleased to announce the twelfth version of Kunena 6.4, a native Joomla extension for Joomla! 5.0, 5.1, 5.2, 5.3, 5.4 and 6.0.
This category may also contain a few topics relating to K 1.6 that may have been moved here possibly by mistake.
The topics in this category are for historical interest only. Owing to the structural differences between K 1.6 and K 1.7, the ideas in these topics may not work with later versions and, for that reason, the topics are locked.
Question Threads from Private Boards showing up in Forum Tab
- standarddamage
-
Topic Author
- Offline
- New Member
-
In Kunena I have 4 forums set up that are only viewable by the staff. The problem I'm running into is that anytime my staff or I post something in one of those forums, the title and forum associated with the post shows up in the "Forums" tab and is viewable by everyone.
Is there a way to set it so that the posts from those private boards don't show up in the "Forum Posts" section of the "Forums" tab? I basically want to set it up so no one can see those posts through that tab.
Please Log in or Create an account to join the conversation.
I assume, when you write "everyone", you mean only registered, logged-in users who have access to the member profiles. Is that correct?In Kunena I have 4 forums set up that are only viewable by the staff. The problem I'm running into is that anytime my staff or I post something in one of those forums, the title and forum associated with the post shows up in the "Forums" tab and is viewable by everyone.
If what you say is correct, this seems to be a bad security flaw in Community Builder. What do the folks at Joomlapolis have to say about this problem? This means you cannot keep any of your forums private! :ohmy:
If your first priority is to stop unauthorised people using a back-door approach to view restricted forums, you must unpublish the CB forum tab now ... at least until the folks at Joomlapolis have provided you with a solution.
Blue Eagle vs. Crypsis reference guide
Read my blog and
Please Log in or Create an account to join the conversation.
- standarddamage
-
Topic Author
- Offline
- New Member
-
- Posts: 13
- Thank you received: 0
I assume, when you write "everyone", you mean only registered, logged-in users who have access to the member profiles. Is that correct?
Yes. Exactly.
If what you say is correct, this seems to be a bad security flaw in Community Builder. What do the folks at Joomlapolis have to say about this problem? This means you cannot keep any of your forums private! :ohmy:
They're actually my next stop. I wanted to make sure that there wasn't something I was doing wrong from the Kunena end, especially seeing as I'm so new to the software.
If your first priority is to stop unauthorised people using a back-door approach to view restricted forums, you must unpublish the CB forum tab now ... at least until the folks at Joomlapolis have provided you with a solution.
The problem is that if I disable that tab, the members won't be able to change their signatures. However, I can set the number of posts to 0 so that none of the posts show up at all for anyone under that tab. Which is probably what I'll end up doing before I open the new Kunena forums.
Thanks for the response, Sozzled, I appreciate it.
Please Log in or Create an account to join the conversation.
Please Log in or Create an account to join the conversation.
There are other alternatives, too, and I would investigate the suggestion made by Hurr1c4n3:The problem is that if I disable that tab, the members won't be able to change their signatures. However, I can set the number of posts to 0 so that none of the posts show up at all for anyone under that tab. Which is probably what I'll end up doing before I open the new Kunena forums.
I rely on Community Builder for user registration, login and for users to choose/upload an avatar. The tabs on the user profiles are useful but they're non-essential and, particularly in your case, one of them creates a significant problem in terms of allowing unauthorised access to confidential and/or sensitive information. That, in my opinion, is an unpardonable sin and demands an immediate solution.You can also unpublish the forumview field in the forum tab of community builder.
For your information, I have set the two relevant Kunena configuration settings thus:
Integration » Avatar Integration » Use avatar picture from = Community Builder
Integration » Profile Settings » Profile = Kunena
With these settings, my users can change their signatures from the Kunena user panel.
Keep us posted on what information you obtain from Joomlapolis.
Blue Eagle vs. Crypsis reference guide
Read my blog and
Please Log in or Create an account to join the conversation.
- standarddamage
-
Topic Author
- Offline
- New Member
-
- Posts: 13
- Thank you received: 0
You can also unpublish the forumview field in the forum tab of community builder.
To my understanding, you can't. It's a system-generated field.
Keep us posted on what information you obtain from Joomlapolis.
I will Sozzled. No answer as of yet.
The thing is that all they would need to do is allow you to pick and choose which forums to publish, which I surprised they overlooked seeing as both Kunena and JFusion allow for that very option in the profiles and modules.
The forum tab has a lot of issues that I hope CB is aware of. If not, I intend to make them aware of them so they can be fixed. There's this, and CB 1.2.1 doesn't recognize the ranks properly either.
Again, thanks for the help, Sozzled.
Please Log in or Create an account to join the conversation.