- Posts: 3
- Thank you received: 0
Logged in user can see other users tickets
- leousa
- Topic Author
- Offline
- New Member
Less
More
9 years 5 months ago #64754
by leousa
Logged in user can see other users tickets was created by leousa
Hi! Great component, thank you!
I did find a security hole and i'm not sure if only i can see this.
Reproduction of the issue (localhost):
User 1 registered and logged in (in browser 1)
User 2 registered and logged in (in browser 2)
Each user submitted a ticket and in ticket list layout each can see only own tickets.
So good so far,
In ticket (detailed view) all looking good...BUT
If logged in user will just type in other user ticket id in the browser address line window - he will see ticket of someone else just as it is his own ticket, including all the privite information, e.g. username, email.
So in link like:
index.php?option=com_helpdeskpro&id=6&layout=default&view=ticket&Itemid=1312
only id number needs to be changed to see any ticket submited by anyone.
Is there a fix for this?
thank you!
I did find a security hole and i'm not sure if only i can see this.
Reproduction of the issue (localhost):
User 1 registered and logged in (in browser 1)
User 2 registered and logged in (in browser 2)
Each user submitted a ticket and in ticket list layout each can see only own tickets.
So good so far,
In ticket (detailed view) all looking good...BUT
If logged in user will just type in other user ticket id in the browser address line window - he will see ticket of someone else just as it is his own ticket, including all the privite information, e.g. username, email.
So in link like:
index.php?option=com_helpdeskpro&id=6&layout=default&view=ticket&Itemid=1312
only id number needs to be changed to see any ticket submited by anyone.
Is there a fix for this?
thank you!
Please Log in or Create an account to join the conversation.
- Tuan Pham Ngoc
- Offline
- Administrator
9 years 5 months ago #64755
by Tuan Pham Ngoc
Replied by Tuan Pham Ngoc on topic Logged in user can see other users tickets
Hi
What version of the extension you are using? We addressed it in version 1.4.0, the security released version which we released last week. Maybe you should update your site to that latest version ?
Tuan
What version of the extension you are using? We addressed it in version 1.4.0, the security released version which we released last week. Maybe you should update your site to that latest version ?
Tuan
Please Log in or Create an account to join the conversation.
- leousa
- Topic Author
- Offline
- New Member
Less
More
- Posts: 3
- Thank you received: 0
9 years 5 months ago #64759
by leousa
Replied by leousa on topic Logged in user can see other users tickets
Yes, i've just noticed 1.4.0 came out. I was using 1.3.0
I'll check if security problem is gone in new version and give feedback on this.
Thanks for promt reply!
I'll check if security problem is gone in new version and give feedback on this.
Thanks for promt reply!
Please Log in or Create an account to join the conversation.
- Tuan Pham Ngoc
- Offline
- Administrator
9 years 5 months ago #64807
by Tuan Pham Ngoc
Replied by Tuan Pham Ngoc on topic Logged in user can see other users tickets
OK. Thanks. I am sure that it is sorted in version 1.4.0 (1.4.0 also offer some other new nice features). But please check and report it back after you checking it
Regards,
Tuan
Regards,
Tuan
Please Log in or Create an account to join the conversation.
- leousa
- Topic Author
- Offline
- New Member
Less
More
- Posts: 3
- Thank you received: 0
9 years 5 months ago #64809
by leousa
Replied by leousa on topic Logged in user can see other users tickets
Confirmed. 1.4.0 has fixed security issues. All good!
Please Log in or Create an account to join the conversation.
- Tuan Pham Ngoc
- Offline
- Administrator
9 years 5 months ago #65041
by Tuan Pham Ngoc
Replied by Tuan Pham Ngoc on topic Logged in user can see other users tickets
Thanks for confirming .
Tuan
Tuan
Please Log in or Create an account to join the conversation.
- Michael Jones
- Offline
- New Member
Less
More
- Posts: 1
- Thank you received: 0
8 years 10 months ago #75070
by Michael Jones
Replied by Michael Jones on topic Logged in user can see other users tickets
i have had this issue also
it started when we upgraded to 1.4.0 version
people can see each other tickets, but its only the users from the before the 1.4 patch was installed
my tickets volume is huge and moving to another ticket system is near impossible
can someone from helpdeskpro support please private massage me or email me
i have been getting ignored and a runaround
its been a while since i complained because support just blew me off
but it is a serious issue and cannot be ignored
it started when we upgraded to 1.4.0 version
people can see each other tickets, but its only the users from the before the 1.4 patch was installed
my tickets volume is huge and moving to another ticket system is near impossible
can someone from helpdeskpro support please private massage me or email me
i have been getting ignored and a runaround
its been a while since i complained because support just blew me off
but it is a serious issue and cannot be ignored
Please Log in or Create an account to join the conversation.
Moderators: Tuan Pham Ngoc
Support
Documentation
Information
Copyright © 2024 Joomla Extensions by Joomdonation. All Rights Reserved.
joomdonation.com is not affiliated with or endorsed by the Joomla! Project or Open Source Matters.
The Joomla! name and logo is used under a limited license granted by Open Source Matters the trademark holder in the United States and other countries.
The Joomla! name and logo is used under a limited license granted by Open Source Matters the trademark holder in the United States and other countries.