-
☆ A M B ☆
- 1,031 Posts
Thanks for reporting. We will look into the code and see how to fix it.
-
☆ A M B ☆
- 117 Posts
Hi Jako,
Seems like Mod_Security is stopping the upload functionality of the KCFinder packaged in MODX 1.0.15 (it didn't in previous versions).
Is there a solution to it without disabling the Mod_Security?
-
☆ A M B ☆
- 2,213 Posts
Quote from: sjmclean at Nov 22, 2014, 03:51 PMIs there a solution to it without disabling the Mod_Security?
Do you know what rules are being triggered? Once you know the offending rule action can be taken to avoid the problem (rewrite the rule, disable the rule, or update the code to avoid triggering the rule).
-
☆ A M B ☆
- 117 Posts
Yes, it's giving the following:
GET:
/manager/media/browser/mcpuk/browse.php?type=images&lng=en&act=upload HTTP/1.1
MESSAGE:
Access denied with code 44 (phase 2). Match of "eq 0" against "MULTIPART_STRICT_ERROR" required. [file "/usr/local/apache/conf/modsec2.conf"] [line "23"] [id "1234123456"] [msg "Multipart request body failed strict validation: PE 0, BQ 0, BW 0, DB 0, DA 0, HF 0, LF 0, SM 0, IQ 0, IP 1, IH 0, FL 0"]
ACTION:
404
Will check with my host.
-
☆ A M B ☆
- 117 Posts
UPDATE
I have added the following in the Mod_Sec and the KCFinder worked:
<Directory /home/user/public_html/manager/media/browser/mcpuk>
SecRuleRemoveById 1234123456
</Directory>
QUESTION
Am I exposing my website to security issues on this website by applying such a rule?
-
☆ A M B ☆
- 2,213 Posts
You are being very specific in disabling the rule in question, so the impact to security should be minimal. I would be interested to know what ruleset (if any) is being used, and what's the actual rule in question. It sounds like there is some aspect of the request getting flagged, which could be correctable.