Clicking on super admin profile opens admin page

  • June 14, 2022 10:04 AM EDT

    When seeing the profile of the super admin or an hyperlink with the name of the super admin, clicking on it opens the /admin page if you are an admin or super admin of the site. For normal users, it returna a page not found.

    This was tested on Widows 11 using Chrome and Edge

    The site is running SE 6.1.1

    • Moderator
    • 6278 posts
    June 15, 2022 5:48 AM EDT

    You named your user super admin? We don't allow spaces in names so that shouldn't have worked. Can you please provide a screenshot of the user name so I can see? Are you using any third party plugins for users or anything?


    This post was edited by Donna at June 15, 2022 5:56 AM EDT
    • Moderator
    • 6278 posts
    June 15, 2022 6:04 AM EDT

    I've tested on my staging and put the First Name as Super and the Last Name as Admin. I then clicked the profile and went to the profile. 

    I then tried putting the username/profile address as superadmin and that also goes to the profile. Neither of these go to the admin panel. Can you please provide more details?

  • June 16, 2022 10:52 AM EDT

    Hi Donna,

    I found the issue. I did set the username to admin and I wasn't facing the issue before. You did ask if I was using third party plugins for users which is not the case, but I realized that a recently added plugin  from Socialnetworking.solutions was providing short member profile URL with their core.

    I tested by renaming the user name and it now works as expected. 

    Thanks, it helps getting a different view of the issue.

    Benoit

     

    • Moderator
    • 6278 posts
    June 21, 2022 9:07 AM EDT

    Thank you Benoit for the details. I'll remove this from the bug tracker and put it in third party discussions.

    • Moderator
    • 6278 posts
    June 21, 2022 9:07 AM EDT

    I hope you let them know of this issue as it might be a security concern.