Please upgrade here. These earlier versions are no longer being updated and have security issues.
HackerOne users: Testing against this community violates our program's Terms of Service and will result in your bounty being denied.
How is users with "Confirm Email" posting activities?
pracddha
New
I hadn't checked my forum for quite a few days. Today when I looked at it, there it was, filled with spammy users and spammy post on activities. But what was surprising is, the users had the confirm email status. And still they were able to make post on activities. Then, I thought it was probably something to do with "permissions". But in permission tab, settings were in such a way that "confirm email" users could only view the activitiy not post them. So, what could have possibly happened.
I use 2.0.18.8 for this forum. Also I use google recaptcha.
Tagged:
0
Comments
this is a duplicate question I believe it has been answered here.
read this discussion:
http://vanillaforums.org/discussion/comment/197625/#Comment_197625
confirm e-mail role could be tightened up by only allowing view for discussions checked and signin allow checked. everything else unchecked in that role. otherwise spammers will be doing what you have experienced.
I may not provide the completed solution you might desire, but I do try to provide honest suggestions to help you solve your issue.