Important: User edit bug

Author Message

Ole Morten Halvorsen

Monday 19 May 2003 4:24:05 am

As many have probably seen here http://ez.no/developer/ez_publish_3/forum/developer/users_editing_their_own_details
a bug was found enabling users to edit other users data. The password can not be changed, but the user account get disabled.

We are working on a fix to this problem now, until then disable the user module. Put this in your site.ini:

[SiteAccessRules]
Rules[]
Rules[]=Access;enable
Rules[]=ModuleAll;true
Rules[]=Access;disable
Rules[]=Module;user

We have disabled the user module here at ez.no, so until the problem is fixed login will not work.

Senior Software Engineer - Vision with Technology

http://www.visionwt.com
http://www.omh.cc
http://www.twitter.com/omh

eZ Certified Developer
http://ez.no/certification/verify/358441
http://ez.no/certification/verify/272578

Jan Borsodi

Monday 19 May 2003 7:13:03 am

A patch for the user edit bug can be found here:
http://ez.no/developer/ez_publish_3/contributions/security_fix_unchecked_user_edit

--
Amos

Documentation: http://ez.no/ez_publish/documentation
FAQ: http://ez.no/ez_publish/documentation/faq

Tony Wood

Monday 19 May 2003 7:43:06 am

Thank you for your fast and efficient resolution of this problem.

Tony Wood : twitter.com/tonywood
Vision with Technology
Experts in eZ Publish consulting & development

Power to the Editor!

Free eZ Training : http://www.VisionWT.com/training
eZ Future Podcast : http://www.VisionWT.com/eZ-Future

Powered by eZ Publish™ CMS Open Source Web Content Management. Copyright © 1999-2014 eZ Systems AS (except where otherwise noted). All rights reserved.

eZ debug

Timing: Jan 18 2025 05:10:59
Script start
Timing: Jan 18 2025 05:10:59
Module start 'layout'
Timing: Jan 18 2025 05:10:59
Module start 'content'
Timing: Jan 18 2025 05:11:00
Module end 'content'
Timing: Jan 18 2025 05:11:00
Script end

Main resources:

Total runtime0.8279 sec
Peak memory usage4,096.0000 KB
Database Queries59

Timing points:

CheckpointStart (sec)Duration (sec)Memory at start (KB)Memory used (KB)
Script start 0.00000.0061 589.0000152.6094
Module start 'layout' 0.00610.0028 741.609439.4141
Module start 'content' 0.00890.8175 781.0234577.2344
Module end 'content' 0.82640.0014 1,358.257812.1797
Script end 0.8278  1,370.4375 

Time accumulators:

 Accumulator Duration (sec) Duration (%) Count Average (sec)
Ini load
Load cache0.00350.4173160.0002
Check MTime0.00150.1833160.0001
Mysql Total
Database connection0.00060.078510.0006
Mysqli_queries0.776993.8466590.0132
Looping result0.00060.0744570.0000
Template Total0.793595.820.3967
Template load0.00220.261820.0011
Template processing0.791395.582220.3957
Template load and register function0.00020.022010.0002
states
state_id_array0.00150.183810.0015
state_identifier_array0.00170.208520.0009
Override
Cache load0.00180.2144200.0001
Sytem overhead
Fetch class attribute can translate value0.00080.095230.0003
Fetch class attribute name0.00200.242450.0004
XML
Image XML parsing0.00110.129530.0004
class_abstraction
Instantiating content class attribute0.00000.002450.0000
General
dbfile0.00080.0947230.0000
String conversion0.00000.001340.0000
Note: percentages do not add up to 100% because some accumulators overlap

Templates used to render the page:

UsageRequested templateTemplateTemplate loadedEditOverride
1node/view/full.tplfull/forum_topic.tplextension/sevenx/design/simple/override/templates/full/forum_topic.tplEdit templateOverride template
3content/datatype/view/ezxmltext.tpl<No override>extension/community_design/design/suncana/templates/content/datatype/view/ezxmltext.tplEdit templateOverride template
3content/datatype/view/ezxmltags/line.tpl<No override>design/standard/templates/content/datatype/view/ezxmltags/line.tplEdit templateOverride template
4content/datatype/view/ezxmltags/paragraph.tpl<No override>extension/ezwebin/design/ezwebin/templates/content/datatype/view/ezxmltags/paragraph.tplEdit templateOverride template
2content/datatype/view/ezimage.tpl<No override>extension/sevenx/design/simple/templates/content/datatype/view/ezimage.tplEdit templateOverride template
1print_pagelayout.tpl<No override>extension/community/design/community/templates/print_pagelayout.tplEdit templateOverride template
 Number of times templates used: 14
 Number of unique templates used: 6

Time used to render debug report: 0.0001 secs