Create article with contents from attached UTF-8 ddos.txt
Try to edit and save it.
Try different PHP max_execution_time from 10 to 60.
Fast saving.
White screen with max execution time reached.
Joomla 3.7.0, JCE Editor Free.
The last executed script is always libraries/vendor/joomla/string/src/phputf8/mbstring/core.php. Lines 41 or 94.
The caller is libraries/joomla/filter/input.php.
Restoring the 'libraries/joomla/filter/input.php', 'libraries/joomla/filter/output.php' to version < 3.7.0 fixes the issue.
That file hasn't changed in 3 years, restoring that file could not "fix" anything.
Sorry, guys, fixed the description of issue.
I confirm the issue, IHAC reporting the same. I was not able to reproduce yet but I believe this is tinymce specific. Initially the user reported that html formatting was not visible in tinymce (just plain text), to workaround the situation I moved the user specific usergroup to "set0" in the tinymce plug-in. The user is part of a sub-set of the Managers with less less priv (mostly restricted to Users, Articles, Categories, Modules and 1-2 core components + one well ranked 3rd party component).
But he is still hitting the time out in libraries/vendor/joomla/string/src/phputf8/mbstring/core.php on line 94
Was working like a charm in 3.6.5. Average articles in French are about 300 characters, so probably not "size" related.
Priority | Urgent | ⇒ | Medium |
Status | New | ⇒ | Discussion |
Category | Administration com_content | ⇒ | Administration com_content com_plugins |
Please provide your full system information provided by Joomla System Information Page
PHP Built On SunOS scmos 5.11 11.1 i86pc
Database Version 5.6.12
Database Collation utf8_general_ci
Database Connection Collation utf8mb4_general_ci
PHP Version 5.5.28
Web Server Apache/2.4.16 (Unix) PHP/5.5.28
WebServer to PHP Interface apache2handler
Joomla! Version Joomla! 3.7.0 Stable [ Amani ] 25-April-2017 15:36 GMT
Joomla! Platform Version Joomla Platform 13.1.0 Stable [ Curiosity ] 24-Apr-2013 00:00 GMT PHP Built On SunOS scmos 5.11 11.1 i86pc
Database Version 5.6.12
Database Collation utf8_general_ci
Database Connection Collation utf8mb4_general_ci
PHP Version 5.5.28
Web Server Apache/2.4.16 (Unix) PHP/5.5.28
WebServer to PHP Interface apache2handler
Joomla! Version Joomla! 3.7.0 Stable [ Amani ] 25-April-2017 15:36 GMT
Joomla! Platform Version Joomla Platform 13.1.0 Stable [ Curiosity ] 24-Apr-2013 00:00 GMT
Please go to example.com/administrator/index.php?option=com_admin&view=sysinfo and click the Download As Text button to download the FULL system information requested, then update this issue with that.
ok to privately email you the file to your github profile email address?
there is no private information in that file
systeminfo-2017-04-28T11_56_49+00_00.txt
Denial of service (HTTP 500 due to max execution time) occurs on server side.
just replaced couple of identifiable info by xxxx..
https://gist.github.com/jsubri/6fa87546086e89725e484ba39f373ff3
Brian, my manual change was just about the template names (my bad, I should not have created the templates with such naming), otherwise the file is unmodified. I'm suspecting the user to enter a strange sequence of characters coming along with a cut&paste likely from word. If I can access to the .doc I'll try to nailed down the sequence and post again.
Status | Discussion | ⇒ | Closed |
Closed_Date | 0000-00-00 00:00:00 | ⇒ | 2017-04-29 06:10:16 |
Closed_By | ⇒ | franz-wohlkoenig |
Closed_By | franz-wohlkoenig | ⇒ | joomla-cms-bot |
Set to "closed" on behalf of @franz-wohlkoenig by The JTracker Application at issues.joomla.org/joomla-cms/15628
closed in favor of #15673
Nothing attached