User permission, every user can access the backend through a edit product button

Started by designkj, August 07, 2019, 04:12:00 AM

Previous topic - Next topic

designkj

Hello

I have VirtueMart 3.4.2 and Joomla 3.9.10 - have been running this Virtuemart for years with regular updates. Now suddenly every user can access the VM backend as the Edit Product button is visible to every Registered user. The edit button is not visible on conventional Joomla pages, only in Virtuemart. I have looked through every table in the DB I can think of but no success... Any history of this or good idea ?

Regards
designkj

Jörgen

Check for front end access rights. And make sure you have not any strange superuser that has been created with an unsecure joomla version.
Jörgen @ Kreativ Fotografi
Joomla 3.9.18
Virtuemart 3.4.x
Olympiantheme Hera (customized)
This reflects current status when viewing old post.

designkj

Thank you. There is no new Admin user, and I cannot see anything suspicious. I have tried to delete all Cache and also did a fresh install on Virtuemart but that didn't solve the problem.

Regards

designkj

I found the Permissions button on top, and there the registered user is allowed access to almost all areas, is there a bug that can cause this or is it more likely that someone has got into the system ?

StefanSTS

Never saw any bug like that.

You might want to run your site through myjoomla or similar to check for hack attempts.
At some time someone must have changed these settings, either someone with given rights, or someone who took the rights.

It might be wise to ask someone experienced to do that (like GJC or so).

Regards
Stefan
--
Stefan Schumacher
www.jooglies.com - VirtueMart Invoice Layouts

Please use only stable versions with even numbers for your live shop! Use Alpha versions only if you know what risk you are taking.

GJC Web Design

GJC Web Design
VirtueMart and Joomla Developers - php developers https://www.gjcwebdesign.com
VM4 AusPost Shipping Plugin - e-go Shipping Plugin - VM4 Postcode Shipping Plugin - Radius Shipping Plugin - VM4 NZ Post Shipping Plugin - AusPost Estimator
Samport Payment Plugin - EcomMerchant Payment Plugin - ccBill payment Plugin
VM2 Product Lock Extension - VM2 Preconfig Adresses Extension - TaxCloud USA Taxes Plugin - Virtuemart  Product Review Component
https://extensions.joomla.org/profile/profile/details/67210
Contact for any VirtueMart or Joomla development & customisation