Jump to content

Ideas on how to fix this small privacy bug in WHMCS?


Recommended Posts

So I realized a couple year ago that the RSS feeds in WHMCS provide a small privacy bug because they allow users outside the WHMCS or users inside WHMCS but who should have no access to updates access to the news and info on the rss feeds.

 

So I solved this issue by renaming announcementsrss.php to announcementsrssi6567688.php and networkissuesrss.php to networkissuesrss245232324.php so now users can't access it or find it.

 

But I realized that these become obsolete and unusable when we upgrade because the old files are placed back. Unfortunately there is no tpl for these files and these RSS files are encoded so the only way to fix it is to rename.... but when a new version comes out we need to manually delete the files or rename them again....

 

I would much rather have a good future-proofing method to solve this privacy bug once and for all. Is there a good method to stop/halt/delete/remove the RSS feeds forever?

Link to comment
Share on other sites

Sorry for my delay. Yes thank you, that is a good way to fix it and I will use this method. It is still not 100% fool-proof because I still manually need to make notes to my staff not to remove those lines if we overwrite things.

 

A cleaner way is to have an option within WHMCS for "Privacy" that allows those to be turned on or off. I use many WHMCS developers for programming, and I can "spy" on their internal messages becasue I know the URLs to visit. So having a Privacy Setting for admins would fix this. I'm sure many WHMCS users are not aware of this leak?

Link to comment
Share on other sites

Join the conversation

You can post now and register later. If you have an account, sign in now to post with your account.

Guest
Reply to this topic...

×   Pasted as rich text.   Paste as plain text instead

  Only 75 emoji are allowed.

×   Your link has been automatically embedded.   Display as a link instead

×   Your previous content has been restored.   Clear editor

×   You cannot paste images directly. Upload or insert images from URL.

×
×
  • Create New...

Important Information

By using this site, you agree to our Terms of Use & Guidelines and understand your posts will initially be pre-moderated