Hi everybody!
https://cmsimple.org/forum/viewtopic.ph ... 2782#p2782 made me aware of a serious flaw regarding the confirmation mails of Advancedform_XH, namely that anybody can send mail on behalf of the “To” address – any mail, not only “harmless” spam, but even mail with indictable contents. This is not a security issue in the strict sense, but comparably dangerous – therefore I'm posting it in this forum.
Therefore I strongly recommend to not use the confirmation mail “feature”, by not providing a thanks-page, and to send confirmation manually, if required.
Advancedform_XH Confimation Mails
Advancedform_XH Confimation Mails
Last edited by cmb on Fri Feb 01, 2019 12:35 pm, edited 1 time in total.
Reason: fix recommendation; see below
Reason: fix recommendation; see below
Christoph M. Becker – Plugins for CMSimple_XH
Re: Advancedform_XH Confimation Mails
Thats all right.
Nevertheless, a clear hint in the help file should be sufficient.
Are such cases known?
What about the XH shop? - Or shops in general?
Is not it possible to order with a "foreign name"?
Nevertheless, a clear hint in the help file should be sufficient.
Are such cases known?
What about the XH shop? - Or shops in general?
Is not it possible to order with a "foreign name"?
Re: Advancedform_XH Confimation Mails
I'm not aware of any misuses, but it appears generally to be a bad idea to let unauthenticated users (almost all shops require registration, I suppose) send arbitrary contents to arbitrary recipients on your behalf. On the other hand, a confirmation mail with Webmaster controlled contents (“We have received your request, and will address it timely”; likely with a disclaimer a là “If you have not sent that request, please …”) might not be an issue.
Christoph M. Becker – Plugins for CMSimple_XH
Re: Advancedform_XH Confimation Mails
Hi Christoph
I do use a Thanks page but sender also gets information email.
B
I can't see how to turn that feature off.not use the confirmation mail “feature”
I do use a Thanks page but sender also gets information email.
B
Re: Advancedform_XH Confimation Mails
Das bedeutet ja eigentlich, dass nur eine Bestätigungsmail gesendet wird, wenn man die Dank-Seite verwendet ???help-file wrote:Dank-Seite: Wenn leer, wird nach dem E-Mail-Versand die gesendete Information angezeigt. Wenn gesetzt und eine Absender E-Mail-Adresse eingegeben wurde, wird der Besucher nach dem E-Mail-Versand auf diese Seite weiter geleitet, und eine Bestätigungs-E-Mail mit den gesendeten Information wird an ihn geschickt.
Das widerspricht doch dem hier:
Verstehe ich da was falsch?
Re: Advancedform_XH Confimation Mails
No, I was confused. Actually, I should have written:
Therefore I strongly recommend to not use the confirmation mail “feature”, by not providing a thanks-page, and to send confirmation manually, if required.
Christoph M. Becker – Plugins for CMSimple_XH