jason229 Posted September 10, 2019 Share Posted September 10, 2019 Hello everybody, We use whmcs and one of client report us strange issue. All clients can log in in our system without password or even with wrong password. So, if the client has an account with us, he can log in easy without typing password or with wrong password. I am not PHP expert I saw on button press it runs dologin.php but I can not look into that as it is encrypted with ion. Any advice or point where I should look to solve this big issue. 0 Quote Link to comment Share on other sites More sharing options...
WHMCS Developer WHMCS Andrew Posted September 11, 2019 WHMCS Developer Share Posted September 11, 2019 Hi Jason, If you are logged in as an admin user, you are able to login as any client without a password, or with any password. Try the same thing again in either an incognito window, or a different browser without an admin session and you will see that a password is required. Andrew 0 Quote Link to comment Share on other sites More sharing options...
jason229 Posted September 11, 2019 Author Share Posted September 11, 2019 Hello. Tried ... it is same... I am not logged as admin at all. So the situation is weird... I can log in without a password or if it is the wrong password if I have email registered in whmcs... Do not know where to look in code to try to find what makes this issue. Maybe some other advice? 0 Quote Link to comment Share on other sites More sharing options...
Recommended Posts
Join the conversation
You can post now and register later. If you have an account, sign in now to post with your account.