Uploaded image for project: 'CiviCRM'
  1. CiviCRM
  2. CRM-5214

security bug when editing own contact record

    Details

    • Type: Bug
    • Status: Done/Fixed
    • Priority: Major
    • Resolution: Fixed/Completed
    • Affects Version/s: 3.0
    • Fix Version/s: 3.0.2
    • Component/s: None
    • Labels:
      None

      Description

      Upon upgrading to 3.0.1, I run into the following problem: Seem to be able to edit most contact records fine, but any edit to my contact record when saved, leads to a non-recoverable error that cannot be cleared. Logins from other browser sessions with fresh caches run into the same message before reaching the home page. Only way I could get the error cleared was to restore database.

      I labeled this major because can't trust the system enough to use it as long as it's there, but there may be an easy fix or workaround. In 2.2.8, I would frequently hit this screen, but found I could log back in successfully. This is not the case in 3.0.1.

      To be clear, this is the familiar message:

      "Sorry. A non-recoverable error has occurred.

      You do not have permission to access this page

      Return to home page."

      Clicking on home page from this screen regenerates the error. Clearing browser cache and starting over deadends to the same error without accessing home page.

        Attachments

          Activity

            People

            • Assignee:
              rajan Rajan P Mayekar
              Reporter:
              willbrownsberger Will Brownsberger
            • Votes:
              0 Vote for this issue
              Watchers:
              1 Start watching this issue

              Dates

              • Created:
                Updated:
                Resolved: