CiviCRM Community Forums (archive)

*

News:

Have a question about CiviCRM?
Get it answered quickly at the new
CiviCRM Stack Exchange Q+A site

This forum was archived on 25 November 2017. Learn more.
How to get involved.
What to do if you think you've found a bug.



  • CiviCRM Community Forums (archive) »
  • Old sections (read-only, deprecated) »
  • Discussion (deprecated) »
  • Alpha and Beta Release Testing »
  • 2.1 Release Testing »
  • major email subscription security flaw?
Pages: [1]

Author Topic: major email subscription security flaw?  (Read 2147 times)

chrism

  • Guest
major email subscription security flaw?
September 23, 2008, 02:28:50 pm
I may be missing something, but just discovered today what seems like a major security flaw in email subscription pages:

Groups that have Mailing List unchecked, and access set to User and User Admin only, can still be accessed from subscription pages when gid=x is set. 

The list are correctly omitted from the mailing list subscription listing when gid is not specified.

To recreate on the demo server:
(See the Administrator sign-up page)
http://drupal.demo.civicrm.org/civicrm/mailing/subscribe?reset=1&gid=1
(but then on the list overall the Administrator page does not show up)
http://drupal.demo.civicrm.org/civicrm/mailing/subscribe?reset=1

It doesn't look like emails are actually being added to the lists, but isn't it the case that they shouldn't show up if access is set to User and User Admin?

Further, I don't seem to be able to successfully sign-up to a mailing list, even when I am supposed to be able.  When I submit the form at
http://drupal.demo.civicrm.org/civicrm/mailing/subscribe?reset=1
with one or more of the Public lists checked I would expect the contact to show up with pending status.

Chris

Donald Lobo

  • Administrator
  • I’m (like) Lobo ;)
  • *****
  • Posts: 15963
  • Karma: 470
    • CiviCRM site
  • CiviCRM version: 4.2+
  • CMS version: Drupal 7, Joomla 2.5+
  • MySQL version: 5.5.x
  • PHP version: 5.4.x
Re: major email subscription security flaw?
September 23, 2008, 04:54:50 pm

hey chris:

can u file an issue for the first one, and we'll take care of it in the next 2.1 release

lobo
A new CiviCRM Q&A resource needs YOUR help to get started. Visit our StackExchange proposed site, sign up and vote on 5 questions

chrism

  • Guest
Re: major email subscription security flaw?
September 23, 2008, 05:41:42 pm
done:  http://issues.civicrm.org/jira/browse/CRM-3603

C

Pages: [1]
  • CiviCRM Community Forums (archive) »
  • Old sections (read-only, deprecated) »
  • Discussion (deprecated) »
  • Alpha and Beta Release Testing »
  • 2.1 Release Testing »
  • major email subscription security flaw?

This forum was archived on 2017-11-26.