XF 2.0 I'm not sure if this is a security issue or an actual bug

jeb35

Well-known member
Somehow a guest has posted on our forum in Administrator chat when its hidden from everyone else. It is a spam post but just curious how the hell he was able to post this in a hidden staff chat area. Guest's shoudn't be able to post and when I'm logged out, I can't see any staff chat areas. I'll post screenshots below of his post and IP related stuff and also node permissions for Admin chat. Should I create a ticket as well?
 

Attachments

  • randy post.webp
    randy post.webp
    67.9 KB · Views: 14
  • randy ip.webp
    randy ip.webp
    64.5 KB · Views: 14
  • rand ip 2.webp
    rand ip 2.webp
    39.6 KB · Views: 13
  • node permissions.webp
    node permissions.webp
    36.1 KB · Views: 16
Are you sure it is not from an addon?

First look at it and it looks like you are running an addon for the "Contact Us", which posts automatically a thread in a designated area you have chosen in ACP. But I could be wrong.
 
Are you sure it is not from an addon?

First look at it and it looks like you are running an addon for the "Contact Us", which posts automatically a thread in a designated area you have chosen in ACP. But I could be wrong.
Oh crap, my bad. We do have that addon installed. And I just checked email for the forum and 2 emails from that person just came through This can be disregarded. Sorry.
 
  • Like
Reactions: sbj
Top Bottom