View Issue Details

IDProjectCategoryView StatusLast Update
2177Composrcore_configurationpublic2016-07-04 20:22
ReporterChris Graham Assigned ToChris Graham  
PrioritynormalSeverityfeature 
Status resolvedResolutionfixed 
Summary2177: Make auto-acknowledge emails optional
DescriptionThe auto-emails (lang strings YOUR_MESSAGE_WAS_SENT_SUBJECT and YOUR_MESSAGE_WAS_SENT_BODY) are sent out when you post a contact request.

However, if you disable CAPTCHA for these forms, these emails can effectively be used as an open relay - as you can put in a fraudulent from address, and the system sends out an email to that address.
TagsType: Security
Attach Tags
Time estimation (hours)1
Sponsorship open

Sponsor

Date Added Member Amount Sponsored

Activities

There are no notes attached to this issue.

Issue History

Date Modified Username Field Change
2016-04-28 01:32 Chris Graham Summary Made auto-acknowledge emails optional => Make auto-acknowledge emails optional
2016-07-04 20:22 Chris Graham Status Not Assigned => Resolved
2016-07-04 20:22 Chris Graham Resolution open => fixed
2016-07-04 20:22 Chris Graham Assigned To => Chris Graham