CiviCRM Community Forums (archive)

*

News:

Have a question about CiviCRM?
Get it answered quickly at the new
CiviCRM Stack Exchange Q+A site

This forum was archived on 25 November 2017. Learn more.
How to get involved.
What to do if you think you've found a bug.



  • CiviCRM Community Forums (archive) »
  • Old sections (read-only, deprecated) »
  • Support »
  • Using CiviCRM »
  • Using CiviMail (Moderator: Piotr Szotkowski) »
  • CiviMail 2.1 issues with track clickthroughs
Pages: [1]

Author Topic: CiviMail 2.1 issues with track clickthroughs  (Read 1130 times)

Chris Burgess

  • Ask me questions
  • ****
  • Posts: 675
  • Karma: 59
CiviMail 2.1 issues with track clickthroughs
September 29, 2008, 03:58:50 pm
I've just opened a couple of tickets against 2.1 (observed on SVN r17296) and am posting here in the hope that other folks can confirm whether they see the same issues, or add any information.

1. Tokens in embedded URLs (eg {contact.checksum}) do not get handled unless Track Clickthroughs is enabled

IMO, using checksums combined with Track Clickthroughs is a security issue.

If you use Track Clickthroughs to send out an email to contacts which contains a checksum, then any contact can access other mailed contacts' checksums by altering the qid value they receive. Therefore checksum URLs should not be used in combination with Track Clickthroughs.

However, Track Clickthroughs appears to be required for tokens in embedded URLs to function at all.

2. URLs containing tokens with Track Clickthroughs are incorrectly stored in the DB

It seems people using Drupal with Clean URLs disabled may not notice this issue , because Drupal's 404 handling in that case means that they end up on the right page anyway. However I believe this will affect standalone and Joomla installations as well as Drupal with Clean URLs enabled. Would appreciate confirmation from anyone who can test this on those systems.
« Last Edit: September 29, 2008, 04:19:25 pm by xurizaemon »
@xurizaemon ● www.fuzion.co.nz

Pages: [1]
  • CiviCRM Community Forums (archive) »
  • Old sections (read-only, deprecated) »
  • Support »
  • Using CiviCRM »
  • Using CiviMail (Moderator: Piotr Szotkowski) »
  • CiviMail 2.1 issues with track clickthroughs

This forum was archived on 2017-11-26.