You need to be logged in to post in the forum - Log In

An active JCE Pro Subscription is required to post in the forum - Buy a Subscription

Support is currently Offline

Official support hours
Monday to Friday
09:00 - 17:00 Europe/London (BST)

Please create a new Ticket and we will get back to you as soon as we can.

#101881 Jcemediabox 2 and admintools: csrf block

Posted in ‘Mediabox’
This is a public ticket

Everybody will be able to see its contents. Do not include usernames, passwords or any other sensitive information.

Latest post by Ryan on Saturday, 07 December 2019 12:23 GMT

Pklinke
After updating to last jcemediabox on monday, admin tools throws lots of csrf errors regarding https://.../plugins/system/jcemediabox/themes/standard/popup.html or tooltip.html

and blocks the visitors.

Ryan
Those files are used in the older version of JCE MediaBox to create the popup layout. They are not used in JCE MediaBox 2.

Please download and install JCE MediaBox 2.0.13 - https://www.joomlacontenteditor.net/downloads/mediabox

Ryan Demmer

Lead Developer / CEO / CTO

Just because you're not paranoid doesn't mean everybody isn't out to get you.

Pklinke

Hi Ryan,

2.0.13 is already installed since Monday. Since Monday this problem occurs.
I checked the folders, but there is no folder /plugins/system/jcemediabox/themes/.

Why are tooltip.html and popup.html still called?

Peter

Attachments

Ryan
Why are tooltip.html and popup.html still called?


They are not used in JCE MediaBox 2.

Please uninstall JCE MediaBox 2, then re-install.

Ryan Demmer

Lead Developer / CEO / CTO

Just because you're not paranoid doesn't mean everybody isn't out to get you.

Pklinke
I did this but no change. Users are still blocked of course call tooltip.html or popup.html.

Peter

Ryan
Please post a link to an example popup.

Ryan Demmer

Lead Developer / CEO / CTO

Just because you're not paranoid doesn't mean everybody isn't out to get you.

Pklinke
https://familie-in-bewegung.de/ueber-uns/vorstand

There is a popup at die lower picture.

Ryan
I'm not seeing an issue when clicking on the popup.

What is displayed when a visitor clicks on the popup?

Ryan Demmer

Lead Developer / CEO / CTO

Just because you're not paranoid doesn't mean everybody isn't out to get you.

Pklinke
Visitor will not see any issue, but he is blocked.

I will try to get more information, on which page it happens.

Peter

Pklinke
Support from Admin tools has analysed:
---

It seems that all the blocks are from users using their mobile phones; moreover there is nothing in the request, it seems that they are requesting the file directly.

My theory is that in this cache mobile phone browser is pre-fetching the page, even if they are guests, triggering Admin Tools protection.
---
So it seems that both files are called in cache.

Were popup.html and tooltip.html available before 2.0.13?

Ryan
---
It seems that all the blocks are from users using their mobile phones; moreover there is nothing in the request, it seems that they are requesting the file directly.

My theory is that in this cache mobile phone browser is pre-fetching the page, even if they are guests, triggering Admin Tools protection.
---
So it seems that both files are called in cache.


That seems a reasonable assessment to me. The user's browser has cached the old MediaBox javascript file, which is attempting to load the popup.html and tooltip.html files when the page loads. This action is then being blocked by Admin Tools.

Were popup.html and tooltip.html available before 2.0.13?


They were included in MediaBox 1.2.x

Ryan Demmer

Lead Developer / CEO / CTO

Just because you're not paranoid doesn't mean everybody isn't out to get you.