Project

General

Profile

Actions

Feature #23050

closed

Install tool password can be overwritten by an extensions' ext_localcconf.php

Added by Helmut Hummel over 14 years ago. Updated almost 10 years ago.

Status:
Closed
Priority:
Should have
Assignee:
Category:
-
Target version:
-
Start date:
2010-06-30
Due date:
% Done:

0%

Estimated time:
PHP Version:
5.2
Tags:
Complexity:
Sprint Focus:

Description

Quote from Bernhard Kraft: ===================================================
I think this should be seen as a security exploit. As a normal admin
should not be able to enter the install tool.

If you deactivate installing of extensions via the install tool
(AllowLocalInstall) so an admin can not install an extension like
quixplorer. And additionally set the "noEdit" flag, then this issue can
of course get avoided.

But I think operators of a site should be aware of this issue. What do
you think?

OTRS:

2010021810000014
(issue imported from #M14935)


Files

14935_trunk.patch (4.06 KB) 14935_trunk.patch Administrator Admin, 2010-07-17 16:24
14935.patch (3.76 KB) 14935.patch Administrator Admin, 2011-01-04 10:04
Actions

Also available in: Atom PDF