This topic has 4 replies, 3 voices, and was last updated 6 years by Radu.

  • Author
  • #200286
     kurve
    Participant

     

    Good day, I am writing to you because I have noticed a security hole with the kleo theme in several places. The problem in particular is a modification of the username in the table of the database of my sites. From one moment to the next, the user_login field of at least 600 users was modified within the user table by the name “dexter”.

    When finding this problem, I communicated with the hosting and they tell me that it is a problem of KLEO and not of the hosting. Can they help me?

    Attachments:
    You must be logged in to view attached files.
    #200325
     Laura
    Moderator

    Hello, will assign the ticket to a higher support level who can help and advise you in your query.
    Thanks! ?

    Hi there!!! Help others from the community and mark any reply as solution if it solved your question. Mark as a solution

    Laura Solanes - Graphic Designer and Web Designer

    Please be patient as I try to answer each topic as fast as i can.

    If you like the theme or the support you've received please consider leaving us a review on Themeforest!

    Always happy to help you 🙂

    #200333
     Radu
    Moderator

    Hi,

    I don’t think kleo does that, look right now at the db and usernames are different (as it should )

    What are the steps to reproduce that kind of issue ?

    Cheers

    Hi there!!! Help others from the community and mark any reply as solution if it solved your question. Mark as a solution
    #200546
     kurve
    Participant

    Hi Radu, now you are differentiating user names because I restored the last backup I had from the Database.
    I have Buddypress installed, and it has happened 2 times on that site. But it has also happened to me in 2 more sites that do not have buddypress. That’s why I estimate it to be some security hole of the theme

    #200554
     Radu
    Moderator

    Hi,

    You can log all you queries until it happens one then look in log maybe you will see what script done that.

    https://stackoverflow.com/questions/303994/log-all-queries-in-mysql

    Cheers
    R

    Hi there!!! Help others from the community and mark any reply as solution if it solved your question. Mark as a solution
Viewing 5 posts - 1 through 5 (of 5 total)

The forum ‘Bugs & Issues’ is closed to new topics and replies.

Log in with your credentials

Forgot your details?