Quote:
Originally Posted by Alfa1
Some of my members discovered an exploit of this mod which allows anyone to find and access all channels, regardless of the permission settings. This is because all the buttons do is:
javascript:display_channel(1);
There are no additional permissions checks and anyone can access our staff chat. All private communication in such channels are in the open.
So all a user has to do is type 'javascript:void(display_channel(1));' in the browser and replace the number 1 by another number, and they are in another channel.
I am still on 2.4.2 though. Has this been fixed in the latest version?
|
Hum I have never been aware of that !
When you say that you enter this in your browser, how do you do it ?
That could be fixed by putting an ajax call to check channel switch permissions. I'll mark this as a bug once you tell me exactly how to reproduce it.
Quote:
Originally Posted by elteejay
I have a dark theme and I'm getting the following bug.
When the user select a color from his usercp and then changes back to default the chats takes black as default color and thus could be bearly unreadable in dark styles.
Any tips or fixes for this? I attempted to reupload the files to reinstall, but that did nothing.
I'm using vb 3.8.5
|
Known bug, will be adressed in next version.
Quote:
Originally Posted by Jollyware
Installed and Admin CP is fine, just a quick question, how do i get this to show on my forum. For some reason the chatbox is not showing.
Im guessing thats its gonna be an easy fix, but I just cant figure it out.
Thanks for your help.
|
Have you set usergroup permissions ?