Skip to Content Skip to Menu

User is logged in as someone else mid session

  • micheleq
  • micheleq
  • OFFLINE
  • Posts: 144
  • Thanks: 22
  • Karma: 6
9 years 4 months ago #266414 by micheleq
:S

This seems like a security issue and I have no idea how it may have happened.

I'm on Joomla 3.4.0, CB 2.0.7, CBSubs 4.0.0-rc.1, Kunena 3.0.7.

I have a private community with a forum, with only paid and approved members. We have about 300 active members which get to see the forum and post.

Today, after one of a users "Robyn" posted in one of the threads, she noticed it was posted as another user "Julie" (who was logged in at the time). Thankfully these are very kind human beings and they let me know right away. "Julie" told me she could edit the post that "Robyn" had just posted which came up in her, "Julie's" name.

"Robyn" told me after seeing that the pot came up in "Julie's" name, she noticed she was logged in as "Julie". She promptly logged out and in again as herself once again. These two people are not acquaintances and live on different continents, so they have never shared credentials much less a computer.

In the database I could see that the post was labeled with "Julie's" username and user id, but the IP address corresponded to "Robyn".

"Robyn" and "Julie" both use iPads (the devices from hell if you ask me).

The only other strange issues I've had in the past was with this same user "Julie" who was seeing the wrong images (switched icons) throughout the site. After clearing cache it went to normal. At the time I blamed this on the way Apple assigns random strings to the cached images (I may be wrong, but that's what I remember seeing some time ago).

This however is another can of worms, and a potential security risk.

I'm not sure what can be done about it, but I just wanted to report it.

Thank you,
Tomás

Please Log in or Create an account to join the conversation.

  • krileon
  • krileon
  • ONLINE
  • Posts: 48477
  • Thanks: 8281
  • Karma: 1443
9 years 4 months ago - 9 years 4 months ago #266423 by krileon
Replied by krileon on topic User is logged in as someone else mid session
CB doesn't handle the user session nor does it handle posting functionality in Kunena in any way. Joomla maintains a users login via a cookie that stores their session token. It then restores their session from that token on page load. CB handles none of this. You may want to check what all extensions you have installed that affect login and session behavior (e.g. authentication plugins, Joomla user plugins, etc..).

I highly recommend reporting the issue to Joomla directly.

Please also note your install is out of date. Latest Joomla is 3.4.1, latest CB is 2.0.9, latest CBSubs is 4.0.0 Stable, and latest Kunena is 4.0.1. So quite literally everything you've installed is outdated. I highly recommend updating everything.


Kyle (Krileon)
Community Builder Team Member
Before posting on forums: Read FAQ thoroughly + Read our Documentation + Search the forums
CB links: Documentation - Localization - CB Quickstart - CB Paid Subscriptions - Add-Ons - Forge
--
If you are a Professional, Developer, or CB Paid Subscriptions subscriber and have a support issue please always post in your respective support forums for best results!
--
If I've missed your support post with a delay of 3 days or greater and are a Professional, Developer, or CBSubs subscriber please send me a private message with your thread and will reply when possible!
--
Please note I am available Monday - Friday from 8:00 AM CST to 4:00 PM CST. I am away on weekends (Saturday and Sunday) and if I've missed your post on or before a weekend after business hours please wait for the next following business day (Monday) and will get to your issue as soon as possible, thank you.
--
My role here is to provide guidance and assistance. I cannot provide custom code for each custom requirement. Please do not inquire me about custom development.
Last edit: 9 years 4 months ago by krileon.
The following user(s) said Thank You: micheleq

Please Log in or Create an account to join the conversation.

Moderators: beatnantkrileon
Powered by Kunena Forum