Vanilla 1 is no longer supported or maintained. If you need a copy, you can get it here.
HackerOne users: Testing against this community violates our program's Terms of Service and will result in your bounty being denied.
Security issue? Unauthenticaticated able to access search
Sheila
✭✭
Hi!
Just posted about an issue with Discussion Tags only to realize that it is same with all; if unauthenticated user is able to 'guess' the url for search page, which is in my case assumably the default one, guest can search users and get a list with them even as in roles it's been set that guests can't access the search tab. Yes, they can't access the search tab but access the actual url.
Hopefully this is fixed soon.
Just posted about an issue with Discussion Tags only to realize that it is same with all; if unauthenticated user is able to 'guess' the url for search page, which is in my case assumably the default one, guest can search users and get a list with them even as in roles it's been set that guests can't access the search tab. Yes, they can't access the search tab but access the actual url.
Hopefully this is fixed soon.
0
Comments
Sorry if I was not clear enough, when it is set that non-members can't browse the forum, naturally they can't access the search either (afaik).
But when I set with guests that they can browse the forum (which is preferred method since I like to provide publicly few forums, Help-page etc.), they can't access anything they are not allowed but search is still available if the url is guessed/ known where it is with Vanilla. And yes, doublechecked that in roles -> Viewable Tabs/Pages -> it is set to 'no' with search.
Hope I haven't understood something wrong with Vanilla's logic but generally no means absolute no in access rules
If this still does make no sense, whisper me and I'll set my forum public for a while and send you the url so you'll be able to test it yourself.
Tested by turning all add-ons off, checked that extensions.php is empty. Still able to access the search as a guest. Sorry, I do see this more as a minor system bug/ flaw in the role logic. Imo the day users have registered and how many posts they have and when the last visit is much more private data than the topic names board has. And this is available to guests if I don't set public browsing to no.
Guess it's good to mention that the Vanilla board I have has it's content imported from Invision. Had to heavily modify the existing Vanilla add-on thou in order to clean all the **** IPB has, meaning snapbacks, system commets etc. and in order to be able to have old posts maintain image paths and multiquotes like they should but really can't see how that would have any effect to this.
edit: Actually, would that do the trick if I set custom url for search page with the page manager and disable the system default search url with .htaccess? Like I know how to disable default seach with .htaccess but guess it's doable.