Products

Solutions

Resources

Partners

Community

Blog

About

QA

Ideas Test

New Community Website

Ordinarily, you'd be at the right spot, but we've recently launched a brand new community website... For the community, by the community.

Yay... Take Me to the Community!

Welcome to the DNN Community Forums, your preferred source of online community support for all things related to DNN.
In order to participate you must be a registered DNNizen

HomeHomeDNN Open Source...DNN Open Source...Module ForumsModule ForumsRepositoryRepositoryHigh Security Issue - non-admins can moderateHigh Security Issue - non-admins can moderate
Previous
 
Next
New Post
6/11/2007 7:16 AM
 

Hi guys,

Update - I have removed the finer details of the problem (sent to the DNN security team)

I had a problem with the DNN 4.50 upgrade with perms, so it may be something behind the scenes, I don't want to mention the site publicly. Is this a known issue at all? Registered Users do not have edit rights on the module (core settings), and for the actual repository settings only Admins can moderate etc.

I also noticed this in the new version, but I don't think it is what I am experiencing:REP-2394 Module Basic Permissions Have No Effect
fixed. permissions are now applied/checked properly

 

 


Entrepreneur

PokerDIY Tournament Manager - PokerDIY Tournament Manager<
PokerDIY Game Finder - Mobile Apps powered by DNN
PokerDIY - Connecting Poker Players

 
New Post
6/11/2007 7:31 AM
 

Got some more info. I tried it on another instance (it's the .10 version btw - DNN 4.5.1) and it does the same thing (so not related to the failed DNN upgrade.

I also tried approving with the logged out user and it DID approve (ie. not just a UI thing). One thing - the logged out user was not able to EDIT the item - only approve or decline it (slightly happier knowing this ;)

 


Entrepreneur

PokerDIY Tournament Manager - PokerDIY Tournament Manager<
PokerDIY Game Finder - Mobile Apps powered by DNN
PokerDIY - Connecting Poker Players

 
New Post
6/11/2007 9:58 AM
 

Since you have direct recreation steps for this issue, I think it would be a good idea to send an e-mail to security@dotnetnuke.com with the full details for recreation.

This will ensure that all members dealing with DNN security are alerted right away.


-Mitchel Sellers
Microsoft MVP, ASPInsider, DNN MVP
CEO/Director of Development - IowaComputerGurus Inc.
LinkedIn Profile

Visit mitchelsellers.com for my mostly DNN Blog and support forum.

Visit IowaComputerGurus.com for free DNN Modules, DNN Performance Tips, DNN Consulting Quotes, and DNN Technical Support Services
 
New Post
6/11/2007 10:14 AM
 

Good call - I wanted to have at least one other person confirm that it is an issue but it can't hurt to alert them now. I have sent the details...


Entrepreneur

PokerDIY Tournament Manager - PokerDIY Tournament Manager<
PokerDIY Game Finder - Mobile Apps powered by DNN
PokerDIY - Connecting Poker Players

 
New Post
6/11/2007 11:18 AM
 

Thanks!

I personally find it best to send these type of things directly there to avoid listing the details of the issue here on the forums....


-Mitchel Sellers
Microsoft MVP, ASPInsider, DNN MVP
CEO/Director of Development - IowaComputerGurus Inc.
LinkedIn Profile

Visit mitchelsellers.com for my mostly DNN Blog and support forum.

Visit IowaComputerGurus.com for free DNN Modules, DNN Performance Tips, DNN Consulting Quotes, and DNN Technical Support Services
 
Previous
 
Next
HomeHomeDNN Open Source...DNN Open Source...Module ForumsModule ForumsRepositoryRepositoryHigh Security Issue - non-admins can moderateHigh Security Issue - non-admins can moderate


These Forums are dedicated to discussion of DNN Platform and Evoq Solutions.

For the benefit of the community and to protect the integrity of the ecosystem, please observe the following posting guidelines:

  1. No Advertising. This includes promotion of commercial and non-commercial products or services which are not directly related to DNN.
  2. No vendor trolling / poaching. If someone posts about a vendor issue, allow the vendor or other customers to respond. Any post that looks like trolling / poaching will be removed.
  3. Discussion or promotion of DNN Platform product releases under a different brand name are strictly prohibited.
  4. No Flaming or Trolling.
  5. No Profanity, Racism, or Prejudice.
  6. Site Moderators have the final word on approving / removing a thread or post or comment.
  7. English language posting only, please.
What is Liquid Content?
Find Out
What is Liquid Content?
Find Out
What is Liquid Content?
Find Out