Kunena 7.0.5 & Kunena 6.4.11 – Security Updates Released

The Kunena team has announce the arrival of Kunena 7.0.5 [K 7.0.5] in stable which is now available for download as a native Joomla extension for J! 5.4.x/6.0.x. This version addresses most of the issues that were discovered in K 6.2 / K 6.3 / K 6.4 and issues discovered during the last development stages of K 7.0.

The Kunena team is also pleased to announce the eleventh version of Kunena 6.4, a native Joomla extension for Joomla! 5.0, 5.1, 5.2, 5.3, 5.4 and 6.0.

Question Panic - users getting moderator messages and access controls not working

More
10 years 7 months ago #169728 by wibbleypants
I can't find a category "Problems with Kunena 3", so I'm hoping I'll get read here.

I've had to shut down our Kunena forums because all of sudden lots of users are receiving messages telling them that they are moderators. Another thing that suddenly started happening is that ex members of a group are receiving these messages and can access categories belonging to the group that they used to be members of. These are private forums and very sensitive, so the group is all of a panic thinking that all and sundry can read sensitive information. I am really stressed out and I'm receiving 10 emails per minute with complaints. Can anybody help PLEASE? Config below:

This message contains confidential information

Database collation check: The collation of your table fields are correct

Joomla! SEF: Enabled | Joomla! SEF rewrite: Enabled | FTP layer: Disabled |

This message contains confidential information
htaccess: Exists | PHP environment: Max execution time: 50000 seconds | Max execution memory: 120M | Max file upload: 40M

Kunena menu details:

Warning: Spoiler!

Joomla default template details : yoo_corona | author: YOOtheme | version: 5.5.14 | creationdate: Unknown

Kunena default template details : Example Template | author: Kunena Team | version: 1.7.2 | creationdate: 2012-01-31

Kunena version detailed: Kunena 3.0.6 | 2014-07-28 [ Tala ]
| Kunena detailed configuration:

Warning: Spoiler!
| Kunena integration settings:
Warning: Spoiler!
| Joomla! detailed language files installed:
Warning: Spoiler!

Third-party components: UddeIM 3.6

Third-party SEF components: None

Plugins: Content - Kunena Discuss 3.0.1

Modules: Kunena Latest 3.0.1 | Kunena Stats 3.0.1 | Kunena Login 3.0.1 | Kunena Search 3.0.1

Please Log in or Create an account to join the conversation.

More
10 years 7 months ago #169729 by wibbleypants
Update: Kunena says all these users are site admins, but they're not! They're just ordinary users. Obviously that's why they're all receiving the messages and have super powers in the forums. Do I have to hack the DB?

Please Log in or Create an account to join the conversation.

More
10 years 7 months ago #169730 by wibbleypants
Update:

It seems that all users with "editor" privs are considered site admins by Kunena. Is this a bug in Kunena?

Please Log in or Create an account to join the conversation.

More
10 years 7 months ago #169733 by 810
K3.0.6 isn't supported anymore. Please update.

check the permissions on the kunena dashboard -> options top right

Please Log in or Create an account to join the conversation.

More
10 years 7 months ago #169734 by wibbleypants

810 wrote: K3.0.6 isn't supported anymore. Please update.


Oh. I always install updates when they appear, but the Joomla update manager hasn't mentioned an update for Kunena.

check the permissions on the kunena dashboard -> options top right


Yup. Only Admin and SU can do anything.

Please Log in or Create an account to join the conversation.

More
10 years 7 months ago #169735 by wibbleypants
Oh, and in config, I have "Enable version check" set to Yes.

Please Log in or Create an account to join the conversation.

Time to create page: 0.292 seconds