CiviCRM Community Forums (archive)

*

News:

Have a question about CiviCRM?
Get it answered quickly at the new
CiviCRM Stack Exchange Q+A site

This forum was archived on 25 November 2017. Learn more.
How to get involved.
What to do if you think you've found a bug.



  • CiviCRM Community Forums (archive) »
  • Old sections (read-only, deprecated) »
  • Support »
  • Using CiviCRM »
  • Using Core CiviCRM Functions (Moderator: Yashodha Chaku) »
  • Registration bypassing required profiles/ fields
Pages: [1]

Author Topic: Registration bypassing required profiles/ fields  (Read 1413 times)

chaos21in

  • Guest
Registration bypassing required profiles/ fields
June 14, 2007, 12:27:01 am
Hi,

I have a weired problem with my site, either it is possible security breach on my site or possible loophole in drupal/ civicrm. I am using drupal version 5.1 and CiviCRM 1.7.9682.

The thing is i created two profiles "Name" and "Address" through civiCRM and made it available at the time of drupal registration. All data fields in these two profiles are mandatory (required). If i try by myself to try to register without filling these fields it gives friendly error messages as what i was expecting, but eventhough i found atleast 6-7 users registered without filling these info. The latest (last) 3 users are few among them. I tried again by myself registering by just providing username and email id but it giving friendly error messages as i was expecting then how come these new users are registering without filling these info.

Please have a look at http://www.thinkindia.co.uk/den/user/register and try by yourself.

Let me know whats the problem. These new users have weired user names and some giving russian email ids (which are not our intended clients) that makes me suspect that possibly somebody trying to do something nasty.

please make it a priority and let me know whats the problem and how to correct it.

regards,
--rafi

Pages: [1]
  • CiviCRM Community Forums (archive) »
  • Old sections (read-only, deprecated) »
  • Support »
  • Using CiviCRM »
  • Using Core CiviCRM Functions (Moderator: Yashodha Chaku) »
  • Registration bypassing required profiles/ fields

This forum was archived on 2017-11-26.