Kunena 7.0.6 & Kunena 6.4.12 – Security Updates Released

The Kunena team has announce the arrival of Kunena 7.0.6 [K 7.0.6] in stable which is now available for download as a native Joomla extension for J! 5.4.x/6.0.x. This version addresses most of the issues that were discovered in K 6.2 / K 6.3 / K 6.4 and issues discovered during the last development stages of K 7.0.

The Kunena team is also pleased to announce the twelfth version of Kunena 6.4, a native Joomla extension for Joomla! 5.0, 5.1, 5.2, 5.3, 5.4 and 6.0.

Topics that are moved into this category are generally considered to be closed. Users may want to add additional information but these topics should not be resurrected in order to discuss new problems or unrelated matters.

Solved Security issue: Users can gain access to restricted categories in Kunena

More
13 years 8 months ago #134798 by sheno1
Hello,

I have a problem with my forum. When people click on an username they can see the recent posts of an user. When regular members click on a officer, they can jump to the officer forum and see everything in there, while they shouldn't be allowed in there. The officer forum is normally only available for the acces level Officers. How can I solve this issue?

Please Log in or Create an account to join the conversation.

More
13 years 8 months ago - 13 years 8 months ago #134815 by sozzled
G'day, sheno1, and welcome to Kunena.

Use Kunena Category Manager and modify the Permissions tab of the category/categories that only your "officer" members should be allowed to access. If you cannot solve the problem yourself, please post a screenshot of the the Permissions tab of one of these categories and we will try to see what you need to change. I hope this helps.
Last edit: 13 years 8 months ago by sozzled.

Please Log in or Create an account to join the conversation.

More
13 years 8 months ago - 13 years 8 months ago #134843 by sheno1
Hi,

No this isn't my problem. The restrictions are working fine, but there's a way to work around it. See the attached image. Hence my title before you changed it ^^.
Last edit: 13 years 8 months ago by sheno1.

Please Log in or Create an account to join the conversation.

More
13 years 8 months ago #134868 by sozzled
In summary what you are saying is:

(1) Login with a non-privileged user account. At this time the account is unable to view topics in restricted categories.

(2) View the profile of another user (a user who has "privileged" access to other categories) and view that user's most recently-posted messages and click the "more" link at the end of the list.

(3) On the next page, the list of available Board Categories includes all the categories that the "privileged" user has access to and now you can access and visit those categories as if you were the "privileged user, including the ability to most messages in those categories.

This is very interesting and I will have to test this for myself.

Please Log in or Create an account to join the conversation.

More
13 years 8 months ago #134869 by sozzled
I changed the subject again to something that I hope is more meaningful. :)

I tested the claim here (at www.kunena.org ) using a test account that has exactly the same access restrictions as sheno1. I was not able to use the method described by sheno1 to gain access to other categories, such as categories that only administrators, forum moderators and other "privileged" account holders can access here. I am not saying that the claims made by sheno1 are false but I would like to say that there is information as yet unknown to us about sheno1's website that may be allowing users there to bypass Kunena's security mechanisms. Until we learn more about these other facts that sheno1 has not shared with us, this remains a deep mystery.

Why is there a problem at your website but not here at this website? Your configuration report may assist us.

The security issue may involve some particular version of Joomla, or another Joomla extension. Until we know more, I really do not have any explanation to offer at this time.

Please Log in or Create an account to join the conversation.

More
13 years 8 months ago - 13 years 8 months ago #134893 by sheno1
I guess I must've done something wrong then. See config:
This message contains confidential information

Database collation check: The collation of your table fields are correct

Legacy mode: Disabled | Joomla! SEF: Enabled | Joomla! SEF rewrite: Disabled | FTP layer: Disabled |

This message contains confidential information
htaccess: Missing | PHP environment: Max execution time: 30 seconds | Max execution memory: 128M | Max file upload: 8M

Kunena menu details:

Warning: Spoiler!

Joomla default template details : rt_quasar | author: RocketTheme | version: 1.0 | creationdate: September 11, 2011

Kunena default template details : NTS KRevista 2.0 | author: 9ThemeStore | version: 2.0.2 | creationdate: 2012-07-08

Kunena version detailed: Kunena 2.0.2 | 2012-09-02 [ Botschafter ]
| Kunena detailed configuration:

Warning: Spoiler!
| Kunena integration settings:
Warning: Spoiler!
| Joomla! detailed language files installed:
Warning: Spoiler!

Third-party components: UddeIM 2.8

Third-party SEF components: None

Plugins: None

Modules: None


I've denied people from viewing the member/officer forum by acces levels. That should be enough right?
Last edit: 13 years 8 months ago by sheno1. Reason: add info

Please Log in or Create an account to join the conversation.

Time to create page: 0.302 seconds