- Posts: 157
- Thank you received: 9
Kunena 7.0.4 Released
The Kunena team has announce the arrival of Kunena 7.0.4 [K 7.0.4] in stable which is now available for download as a native Joomla extension for J! 5.4.x/6.0.x. This version addresses most of the issues that were discovered in K 6.2 / K 6.3 / K 6.4 and issues discovered during the last development stages of K 7.0
Question Users logged into other users accounts
6 years 8 months ago #210910
by xreliable
Replied by xreliable on topic Users logged into other users accounts
still happening on my site. I'm pretty nervous about this. Seems like a MAJOR security problem.
Please Log in or Create an account to join the conversation.
6 years 8 months ago #210929
by xreliable
Replied by xreliable on topic Users logged into other users accounts
still happening. there are no permissions problems. I have no old or outdated components or plugins. Everything is up to date. I have purged the users sessions multiple times as well as caches. I ran database tools on the tables. Every user who reported this was using kunena. The last report was a few minutes ago. Is there anything else that I can check?
Please Log in or Create an account to join the conversation.
6 years 8 months ago #210997
by xreliable
Replied by xreliable on topic Users logged into other users accounts
still happening
Please Log in or Create an account to join the conversation.
- YourFavoriteSpamBot
-
- Offline
- New Member
-
Less
More
- Posts: 14
- Thank you received: 0
6 years 8 months ago #211080
by YourFavoriteSpamBot
Replied by YourFavoriteSpamBot on topic Users logged into other users accounts
Could you provide some technical details or more information of any sort?
If this is a general issue, that would be a huge security risk and might force me to temporarily take a site down...
If this is a general issue, that would be a huge security risk and might force me to temporarily take a site down...
Please Log in or Create an account to join the conversation.
6 years 8 months ago - 6 years 8 months ago #211082
by xreliable
Replied by xreliable on topic Users logged into other users accounts
I did provide details to the Kunena team but here are some details: When I first experienced this it was using a LitespeedPHP / mariaDB server php v 7.2.20 Latest versions of Kunena/Paid Blue Eagle, and Joomla and EasySocial.
Getting no feedback here from the Kunena team I checked other sources. Apparently this issue has appeared over the years with Joomla for different reasons but almost always as far as I can tell, in conjunction with some sort of caching.
Other than the default Joomla memcache memcached, I was not and am not using any sort of caching. Even on the Litespeed server I was not using the Litespeed joomla plugin.
I moved the site off of Litespeed in case that was the problem to a standard LAMP apache/mysql php 7.2. Not only did this not resolve the problem but almost immediately after moving the site to the new server and only a few users actually logged in, the problem reappeared. It was a minor example of a kunena post displaying in the EasySocial stream by the wrong user but as it was a post from my Joomla administrator account shown as being posted by a regular user, it was a massive disappointment.
I am really disappointed and surprised even, that this issue isn't taken seriously here. It seems like such a massive FUBAR problem that demands attention but I've gotten nothing.
Getting no feedback here from the Kunena team I checked other sources. Apparently this issue has appeared over the years with Joomla for different reasons but almost always as far as I can tell, in conjunction with some sort of caching.
Other than the default Joomla memcache memcached, I was not and am not using any sort of caching. Even on the Litespeed server I was not using the Litespeed joomla plugin.
I moved the site off of Litespeed in case that was the problem to a standard LAMP apache/mysql php 7.2. Not only did this not resolve the problem but almost immediately after moving the site to the new server and only a few users actually logged in, the problem reappeared. It was a minor example of a kunena post displaying in the EasySocial stream by the wrong user but as it was a post from my Joomla administrator account shown as being posted by a regular user, it was a massive disappointment.
I am really disappointed and surprised even, that this issue isn't taken seriously here. It seems like such a massive FUBAR problem that demands attention but I've gotten nothing.
Last edit: 6 years 8 months ago by xreliable.
Please Log in or Create an account to join the conversation.
Time to create page: 0.252 seconds