Jump to content

Anonymous guests can create and view tickets


mustardman

Recommended Posts

Pretty sure this was not possible before updating to v6.3. WHMCS support is trying to tell me this is normal. Not sure what is normal about anonymous internet people able to access my ticket system without having to log in. They don't even have to use captcha. Just have to create the ticket by email first. So they can automate it and create SPAM quite easily I would think.

 

To reproduce send an email to your WHMCS support email from an email account not associated with any clients on the system. WHMCS will create a ticket and send a reply using the "Support Ticket Opened" template. When you get the reply just click on the link and view the ticket. No login of any sort require. No captcha even though I have that enabled. I also have Setup > General Settings > Support > Client Tickets Require Login checked.

 

According to their documentation this should not be possible when that box is checked although they tell me I am interpreting that wrong. Seems pretty clear to me and I am pretty sure that is how it worked before updating to v6.3

 

This is great for SPAMMERS. All they have to do is send emails to your WHMCS system and keep changing the "From" email header and your system will reply to whomever they make the "From" out to be. Not only that but they can view the ticket and change that email again. Thus it gives them twice the SPAMMING power and all easily automated with no captcha checks.

Edited by mustardman
Link to comment
Share on other sites

Join the conversation

You can post now and register later. If you have an account, sign in now to post with your account.

Guest
Reply to this topic...

×   Pasted as rich text.   Paste as plain text instead

  Only 75 emoji are allowed.

×   Your link has been automatically embedded.   Display as a link instead

×   Your previous content has been restored.   Clear editor

×   You cannot paste images directly. Upload or insert images from URL.

  • Recently Browsing   0 members

    • No registered users viewing this page.
×
×
  • Create New...

Important Information

By using this site, you agree to our Terms of Use & Guidelines and understand your posts will initially be pre-moderated