Support

Admin Tools

#26405 Admin tools 4.0.2 update and query

Posted in ‘Admin Tools for Joomla! 4 & 5’
This is a public ticket

Everybody will be able to see its contents. Do not include usernames, passwords or any other sensitive information.

Environment Information

Joomla! version
n/a
PHP version
n/a
Admin Tools version
n/a

Latest post by on Sunday, 27 November 2016 17:17 CST

user79996
 Hello Nicholas,

Heartiest congratulations
My wishes are - Let you never once pause to measure your love and always find magic in each other's hands!

I have 2 Questions
in admin tools latest update changelog its mentijned - MITIGATION FOR JOOMLA SECURITY ISSUE. Joomla 3.4.4 to 3.6.3 (inclusive) has a security vulnerability which allows unauthenticated users to register users with any user group except Super User. This is a high priority security issue ....... If, for any reason, you cannot update immediately to Joomla! 3.6.4 or later please install Admin Tools 4.0.2 to protect your site.

My Question is
> Updated to admin tools 4.0.2. - Is there any setting which needs to be tweaked in for WAF Blacklist rule so as to stop this kind of attack on the security issue of the site

Second Question (though unrelated - but if can guide)
I earlier Updated from joomla 2.5 to Joomla 3.6.2 last month,
Now in joomla 3.6.2 - Trying to embed video in joomla 3.6.2 - but iframe tags and the code in it are stripped on saving (it was working fine in joomla 2.5.28)

Did following Check :-

1. removed iframe from prohibitor element in Tinmce editor in advanced plugin settings

2 Check Text Filter settings - its having no restriction for super user

3 No other security tool installed other than akeeba admin tools - no such setting to disallow iframe

Checked field settings - its

<field name="n_long_description" type="editor" buttons="true" filter="safehtml" label="NEWS" description="NEWS DESCRIPTION" hint="Detail" required="true"/>

If can advise why is iframe tag been removed on saving or a setting which needs to be checked

Many thanks

tampe125
Akeeba Staff
Hello,

  1. WAF Blacklist rules are enabled by default. So you simply have to update to the latest version to get them
  2. I suspect such issue is caused by your editor. Please disable Admin Tools system plugin, the IFRAME is still removed? If so, the problem is not caused by Admin Tools, you should seek assistance in Joomla forums.

Davide Tampellini

Developer and Support Staff

🇮🇹Italian: native 🇬🇧English: good • 🕐 My time zone is Europe / Rome (UTC +1)
Please keep in mind my timezone and cultural differences when reading my replies. Thank you!

System Task
system
This ticket has been automatically closed. All tickets which have been inactive for a long time are automatically closed. If you believe that this ticket was closed in error, please contact us.

Support Information

Working hours: We are open Monday to Friday, 9am to 7pm Cyprus timezone (EET / EEST). Support is provided by the same developers writing the software, all of which live in Europe. You can still file tickets outside of our working hours, but we cannot respond to them until we're back at the office.

Support policy: We would like to kindly inform you that when using our support you have already agreed to the Support Policy which is part of our Terms of Service. Thank you for your understanding and for helping us help you!