?
avatar oe-bayram
oe-bayram
18 Apr 2017

To check which pages my visitors are visiting, I installed Piwik and sometimes I look there what is happening.
Now I have figured out that someone has tried to visit some protected pages without logging in, such as image upload page.

Steps to reproduce the issue

mysite.com/index.php?option=com_media&view=imagesList&tmpl=component&folder=&asset=com_content&author=

Expected result

404 Error page, saying that you have no access to this page

Actual result

You can upload images without login !!!

System information (as much as possible)

Datenbankversion: 5.6.35-log
PHP-Version: 7.0.16
Webserver: Apache/2.2.31 (Unix)
Joomla version: Joomla! 3.6.5 Stable
Joomla!-Plattform-Version: Joomla Platform 13.1.0 Stable

Additional comments

avatar oe-bayram oe-bayram - open - 18 Apr 2017
avatar joomla-cms-bot joomla-cms-bot - labeled - 18 Apr 2017
avatar brianteeman
brianteeman - comment - 18 Apr 2017

I can not confirm this (not tested with a t3 template)

avatar mbabker
mbabker - comment - 18 Apr 2017

Your site's ACL is misconfigured.

avatar brianteeman
brianteeman - comment - 18 Apr 2017

If i remember correctly this can only happen if you have changed the ACL permissions for the media manager from the default settings to allow a guest to upload images. This is not an issue with Joomla but with your specific web site

avatar brianteeman brianteeman - change - 18 Apr 2017
Status New Closed
Closed_Date 0000-00-00 00:00:00 2017-04-18 20:57:44
Closed_By brianteeman
avatar brianteeman brianteeman - close - 18 Apr 2017

Add a Comment

Login with GitHub to post a comment