VirtueMart Forum

VirtueMart 2 + 3 + 4 => General Questions => Topic started by: designkj on August 07, 2019, 04:12:00 AM

Title: User permission, every user can access the backend through a edit product button
Post by: designkj on August 07, 2019, 04:12:00 AM
Hello

I have VirtueMart 3.4.2 and Joomla 3.9.10 - have been running this Virtuemart for years with regular updates. Now suddenly every user can access the VM backend as the Edit Product button is visible to every Registered user. The edit button is not visible on conventional Joomla pages, only in Virtuemart. I have looked through every table in the DB I can think of but no success... Any history of this or good idea ?

Regards
designkj
Title: Re: User permission, every user can access the backend through a edit product button
Post by: Jörgen on August 07, 2019, 10:23:43 AM
Check for front end access rights. And make sure you have not any strange superuser that has been created with an unsecure joomla version.
Jörgen @ Kreativ Fotografi
Title: Re: User permission, every user can access the backend through a edit product button
Post by: designkj on August 07, 2019, 11:44:43 AM
Thank you. There is no new Admin user, and I cannot see anything suspicious. I have tried to delete all Cache and also did a fresh install on Virtuemart but that didn't solve the problem.

Regards
Title: Re: User permission, every user can access the backend through a edit product button
Post by: designkj on August 07, 2019, 12:23:01 PM
I found the Permissions button on top, and there the registered user is allowed access to almost all areas, is there a bug that can cause this or is it more likely that someone has got into the system ?
Title: Re: User permission, every user can access the backend through a edit product button
Post by: StefanSTS on August 07, 2019, 12:33:04 PM
Never saw any bug like that.

You might want to run your site through myjoomla or similar to check for hack attempts.
At some time someone must have changed these settings, either someone with given rights, or someone who took the rights.

It might be wise to ask someone experienced to do that (like GJC or so).

Regards
Stefan
Title: Re: User permission, every user can access the backend through a edit product button
Post by: GJC Web Design on August 07, 2019, 12:46:08 PM
perhaps a read thru of this topic might give some clues

http://forum.virtuemart.net/index.php?topic=138033
Title: Re: User permission, every user can access the backend through a edit product button
Post by: designkj on August 07, 2019, 12:48:26 PM
Thanks everyone for your kind help :-)