View Issue Details
| ID | Project | Category | View Status | Date Submitted | Last Update |
|---|---|---|---|---|---|
| 13366 | Bug reports | Theme editor | public | 2018-02-16 00:07 | 2018-03-09 16:36 |
| Reporter | RichieB | Assigned To | |||
| Priority | none | Severity | minor | ||
| Status | closed | Resolution | fixed | ||
| Product Version | 3.1.x | ||||
| Summary | 13366: Extending a theme creates world writable directories | ||||
| Description | When extending a theme a new directory tree upload/themes/survey/<name> get's created. All subdirectories below this new path are world writable which is bad security practice. | ||||
| Steps To Reproduce |
| ||||
| Tags | No tags attached. | ||||
| Bug heat | 6 | ||||
| Complete LimeSurvey version number (& build) | 3.2.0+180206 | ||||
| I will donate to the project if issue is resolved | No | ||||
| Browser | |||||
| Database type & version | mysql 5.7.21-0ubuntu0.16.04.1 | ||||
| Server OS (if known) | Ubuntu 16.04.1 | ||||
| Webserver software & version (if known) | apache 2.4.18-2ubuntu3.5 | ||||
| PHP Version | 7.0.22-0ubuntu0.16.04.1 | ||||
|
It's rather a server configuration problem. |
|
|
No, it is set to mode 0777 explicitly by several places in the php code like: |
|
|
ok... thank you very much |
|
|
Fix committed to master branch: http://bugs.limesurvey.org/plugin.php?page=Source/view&id=26667 |
|
|
Version 3.5.0 180309 released |
|
| Date Modified | Username | Field | Change |
|---|---|---|---|
| 2018-02-16 00:07 | RichieB | New Issue | |
| 2018-02-16 10:24 |
|
Note Added: 46544 | |
| 2018-02-16 15:13 | RichieB | Note Added: 46551 | |
| 2018-02-16 15:20 |
|
Note Added: 46552 | |
| 2018-03-05 11:41 |
|
Sticky Issue | No => Yes |
| 2018-03-05 18:33 |
|
Changeset attached | => LimeSurvey master a53d5b14 |
| 2018-03-05 18:33 |
|
Note Added: 46910 | |
| 2018-03-05 18:33 |
|
Assigned To | => LouisGac |
| 2018-03-05 18:33 |
|
Resolution | open => fixed |
| 2018-03-05 18:37 |
|
Sticky Issue | Yes => No |
| 2018-03-05 18:37 |
|
Status | new => resolved |
| 2018-03-09 16:36 | c_schmitz | Note Added: 46991 | |
| 2018-03-09 16:36 | c_schmitz | Status | resolved => closed |