![]() |
It's in the AdminCP. It is the percentage they get per night.
|
That was the first place I looked...I can't find this option anywhere. Is it the "Action Manager"? If so, then it isn't so obvious as the field would be "Tax" not "Interest", so I don't think that is the correct area...
It's definitely not the UTT Point System Settings or the UTT Store Settings. |
There is a major exploit in this hack that will let users donate virtually unlimited amounts of points to themselves or other users and only be charged a minimum amount. It's a simple technique for those who know how to do it, so it's important to fix this or your currency system will be pretty much useless! It does show up in the action transaction logs, so check them for funny entries in the point column.
FIX- In uttstore/action.donate.php, look for both instances of this line: $_FIELDS = uttstore_globalize_fields($fields); ADD THIS LINE AFTER: $_FIELDS['points'] = uttpoints_number_format($_FIELDS['points']); It's also a good idea to turn off reputation for donating points since a user can donate all their points to themselves over and over and get unlimited reputation. |
Quote:
I am fairlay sure we fixed this problem. |
Quote:
I just downloaded the latest release from geekydesigns and can still donate to myself. |
Quote:
|
Quote:
Regular donate. :) *edit* *checks* Yup. Regular donate. |
Quote:
The problem is NOT that the user can donate to themselves, but rather can put a very simple string into the "How much would you like to donate?" field and give themselves (or anyone) many more points than it should send. For obvious reasons I won't post how here, but I will PM Zachary with details. The simple fix I mentioned in my previous post patches this major exploit. |
Installed! :) This is great! I had one "for each" error when I first opened the bank page. But a refresh on the page and the error is gone...
|
Quote:
|
All times are GMT. The time now is 05:01 PM. |
Powered by vBulletin® Version 3.8.12 by vBS
Copyright ©2000 - 2025, vBulletin Solutions Inc.
X vBulletin 3.8.12 by vBS Debug Information | |
---|---|
|
|
![]() |
|
Template Usage:
Phrase Groups Available:
|
Included Files:
Hooks Called:
|