Announcement

Collapse
No announcement yet.

New problem with Edit User from User Profile

Collapse
X
Collapse
First Prev Next Last
 
  • Filter
  • Time
  • Show
Clear All
new posts

    New problem with Edit User from User Profile

    Not sure what to inform our Host/Owner about this.

    This started today. When I click on the pencil icon, I'm receiving a Forbidden notice. This has never occurred before.

    Click image for larger version

Name:	Screen Shot 2024-08-01 at 2.20.29 PM.png
Views:	2020
Size:	92.7 KB
ID:	30188Click image for larger version

Name:	Screen Shot 2024-08-01 at 2.20.54 PM.png
Views:	98
Size:	46.8 KB
ID:	30189
    The Linux Community has given me much. I do what I can to return the favor!

    #2
    Someone also reported the same issue for a vB6 forum. I couldn't figure out why but I fixed it by updating the Edit User link in the template to point directly to the AdminCP profile page instead of the AdminCP index page with frames. Not an ideal solution but it worked.
    Buy me a coffeePayPal QR Code
    My Amazon Affiliate Link
    Fast vBulletin VPS Host:
    This site is hosted by IONOS

    Comment


      #3
      Originally posted by glennrocksvb View Post
      I couldn't figure out why but I fixed it by updating the Edit User link in the template to point directly to the AdminCP profile page instead of the AdminCP index page with frames.
      Will you be updating the MOD, or provide the change in a reply so we can make the edit ourselves?
      The Linux Community has given me much. I do what I can to return the favor!

      Comment


        #4
        I think there's a better solution without editing a template. I will try it and post the solution.
        Buy me a coffeePayPal QR Code
        My Amazon Affiliate Link
        Fast vBulletin VPS Host:
        This site is hosted by IONOS

        Comment


          #5
          Originally posted by Snowhog;n30187

          This started today. When I click on the pencil icon, I'm receiving a Forbidden notice. This has never occurred [/ATTACH
          Hi..

          I noticed this issue is fixef in 6.0.6.

          Regards.

          Comment


            #6
            Originally posted by webmsg View Post
            I noticed this issue is fixef in 6.0.6.
            You're right. I found the bug tracker for it.



            As Kevin Sours mentioned in the ticket, this issue also affects other AdminCP links that point to frames index page (admincp/index.php?loc=admincp/xxxxx/xxxxx). For example, the settings link in the Products & Hooks page.
            Last edited by glennrocksvb; 08-11-2024, 10:30 PM.
            Buy me a coffeePayPal QR Code
            My Amazon Affiliate Link
            Fast vBulletin VPS Host:
            This site is hosted by IONOS

            Comment


              #7
              Hoping they will fix this for vB5 too.
              The Linux Community has given me much. I do what I can to return the favor!

              Comment


                #8
                I don't think they will since they no longer make development for vB5 unless it's a vBulletin security-related issue. But who knows. Maybe you can post in that topic and ask?

                Btw, I checked how they fixed the issue in vB 6.0.6.

                Starting vB 6.0.6, the Edit User link (and other similar links) had changed

                from: (userid=1 used as example)

                Code:
                https://yourdomain.com/admincp/index.php?loc=admincp%2Fuser.php%3Fdo%3Dedit%26u%3D1
                to:

                Code:
                https://yourdomain.com/admincp/index.php?locfile=user&locparams%5Bdo%5D=edit&locparams%5Bu%5D=1
                Apparently, the issue started when Apache made a change on the server where passing a URL on the querystring (admincp%2Fuser.php%3Fdo%3Dedit%26u%3D1 in the sample URL above) runs afoul of some security restrictions on Apache mod_rewrite. This change caused the HTTP Forbidden 403 error. The solution made by vB was to change the format of the querystring to pass the parts of the URL separately like locfile=user and locparams%5Bdo%5D=edit and locparams%5Bu%5D=1. From the separate querystring parameters, it would join them together and generate the full URL.



                Last edited by glennrocksvb; 08-11-2024, 11:20 PM.
                Buy me a coffeePayPal QR Code
                My Amazon Affiliate Link
                Fast vBulletin VPS Host:
                This site is hosted by IONOS

                Comment


                  #9
                  Thank you for the update and information as to the cause. I asked on vBulletin Forums: https://forum.vbulletin.com/forum/vb...le-not-working

                  On the assumption that their response is 'No', and seeing as you know how they fixed the issue in vB 6.0.6, will you be able to create a MOD or CSS to 'fix' it for users of vB 5.7.5? We are of course, able to work around this issue; access the user from AdminCP; so it (this issue) isn't a show stopper. It is however, inconvenient.
                  The Linux Community has given me much. I do what I can to return the favor!

                  Comment


                    #10
                    Wayne Luke replied and said "Most likely not."

                    The issue isn't one of vBulletin's making; it is the direct result of:
                    Apache HTTP Server weakness with encoded question marks in backreferences
                    ​ (See: https://www.cve.org/CVERecord?id=CVE-2024-38474).

                    He further said:
                    Apache does allow you to disable the its new security features in 2.4.61 and higher. You would have to google this (Apache Allow 3F) and update the main redirect rule on your site. If you do make this change, I highly recommend that you secure your AdminCP, enable Two-Factor Authentication and/or IP Address lockdown in your /core/includes/config.php file.
                    For now, I'll just login to the AdminCP and review suspect new users there.
                    The Linux Community has given me much. I do what I can to return the favor!

                    Comment

                    Latest Posts

                    Collapse

                    Working...
                    X
                    Searching...Please wait.
                    An unexpected error was returned: 'Your submission could not be processed because you have logged in since the previous page was loaded.

                    Please push the back button and reload the previous window.'
                    An unexpected error was returned: 'Your submission could not be processed because the token has expired.

                    Please push the back button and reload the previous window.'
                    An internal error has occurred and the module cannot be displayed.
                    There are no results that meet this criteria.
                    Search Result for "|||"