Welcome, Guest
Username: Password: Remember me

TOPIC:

JED says there is a problem with JEM. Is it correct? 7 years 7 months ago #19324

  • jojo12
  • jojo12's Avatar Topic Author
  • Offline
  • Administrator
  • Administrator
  • Posts: 3542
  • Thank you received: 404
VEL=Vulnerable Extensions List!

Please Log in or Create an account to join the conversation.

JED says there is a problem with JEM. Is it correct? 7 years 7 months ago #19327

Hi there

What about Jem 3.0.7, has it the same security issues ??

Please Log in or Create an account to join the conversation.

JED says there is a problem with JEM. Is it correct? 7 years 7 months ago #19328

@znort

What about Jem 3.0.7, has it the same security issues ??

actually it's 1 problem but a package should be created there too. But JEM 3.x is not for public release here at the site. will create a package later at Github.


ah well as it's already in the open air i guess it doesn't heart to tell what's going on and how you can change things.

Someone did report 2 problems:
- 1 with the default allowed attachment-types (Settings->Global Parameters-> setting "default parameters")
the thing is that the default setting did allow attachments as html/php etc. But actually it's a setting and a admin should always check the needed settings. It's now changed and the default won't allow it anymore.

- the second one is more complicated.
It's about the myevents-view and then function publish and someone needs to be logged in.
file: components/com_jem/models/myevents

To see the needed changes you can take a peak over here:
github.com/jemproject/JEM-Project/commit...72ce42d595f7ca7299ae
it's now using code that Joomla is also using for the publish function.
(won't respond to PM)
==================================================================
running: pre-alpha JEM 4.x (custom version) + Joomla 4.0.0-beta7 + PHP 7.3
The following user(s) said Thank You: znort

Please Log in or Create an account to join the conversation.

Last edit: by Bluefox.

JED says there is a problem with JEM. Is it correct? 7 years 7 months ago #19398

  • jojo12
  • jojo12's Avatar Topic Author
  • Offline
  • Administrator
  • Administrator
  • Posts: 3542
  • Thank you received: 404
VEL says now the problem is solved. See
vel.joomla.org/resolved/1733-event-manag...-1-4-and-below-other

now it's on JED to put us back on list.

Please Log in or Create an account to join the conversation.

JED says there is a problem with JEM. Is it correct? 7 years 7 months ago #19403

I just tried to download JEM 2.1.4.2 "pkg_jem_v2.1.4.2.zip". Doing this Google Chrome gives the error: ".. ist ein ungewöhnlicher Download und könnte schädlich sein."

Please clarify that the download is not compromised.

Thank you
HaPott

Please Log in or Create an account to join the conversation.

JED says there is a problem with JEM. Is it correct? 7 years 7 months ago #19404

  • Hoffi
  • Hoffi's Avatar
  • Offline
  • Platinum Member
  • Platinum Member
  • Posts: 2279
  • Thank you received: 449
Hi HaPott,

I just downloaded the file from www.joomlaeventmanager.net/download (with Firefox). It's exactly the package I produced. Also my virus scanner hadn't found any problem.

So I don't know what's Chrome's problem is.

Just to ensure we talk about the same file (excluding a "man in the middle"):
SHA-1: e7ae87fcc4103d24b78b58f594b82c55069f7228
MD5: d4cf590a888b54e00bd6fbb39fc2bf0b
Pessimists are optimists with experience!
The following user(s) said Thank You: HaPott

Please Log in or Create an account to join the conversation.

Time to create page: 0.482 seconds

Donate

If you find JEM useful and if you use it on your site, please consider a donation to the project.

Private Messages

You are not logged in.

Follow us......