Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Security: Anonymous access to 'Sites Management' even in 'NO ACCESS' mode #635

Closed
anonymous-matomo-user opened this issue Mar 28, 2009 · 2 comments
Labels
Bug For errors / faults / flaws / inconsistencies etc. wontfix If you can reproduce this issue, please reopen the issue or create a new one describing it.

Comments

@anonymous-matomo-user
Copy link

Anonymous users can still access the site management section of Piwik even when they have been restricted with ‘No Access’

Calling the URL’s;

/index.php?module=SitesManager&action=displayJavascriptCode&idsite=1

/index.php?module=SitesManager&action=index&idsite=1

/index.php?module=Feedback&action=index&idsite=1&keepThis=true&TB_iframe=true&height=400&width=350

Will all display results with out authentication.

Other pages maybe affected, but these are the ones I know of.

The data exposed isn’t critical but still poses a minor security issue.

@robocoder
Copy link
Contributor

The tracker code is public information.

The site manager page may be accessible, but it doesn’t display any site information to which the anonymous user has ‘no access’. I suppose we could restrict access to even this page.

The feedback module is for the public to submit feedback. If you read the plugin description from the plugin admin screen, it reads:

```
Send your Feedback to the Piwik Team in one click. Share your ideas and suggestions with us! By Piwik.
```

You’re welcome to deactivate this plugin.

@robocoder
Copy link
Contributor

Oops. Given ticket #554, we won’t be blocking access to the site manager page.

This issue was closed.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
Bug For errors / faults / flaws / inconsistencies etc. wontfix If you can reproduce this issue, please reopen the issue or create a new one describing it.
Projects
None yet
Development

No branches or pull requests

3 participants