Exploit discovered / permissions issue #3


  • Accepted
  • Other
Open
Assigned to _ForgeUser7258426
  • _ForgeUser10818040 created this issue Jan 26, 2014

    Hi,
    Thanks for a really great plugin that has made my server so much easier to run!
    Just thought I'd let you know, though. My players have discovered they can exploit the Admin360 to get free teleports.
    Regular players can see the ticket submitted messages, and they can do /a3 next to teleport to their friend if their friend submits a ticket.
    Also, if a server staff enters /a3 count to see outstanding tickets, they get told they don't have the Admin360.Count permission.

    Server is running Spigot (build 1278)
    Using bPermissions v 2.10.7
    Admin360 v 2.0.0

    Regular players have only the Admin360.player node
    Server staff have both Admin360.player and Admin360.admin

    No errors appear in the logs.

    I do see in the plugin.yml that there is an entry saying softdepend: [PermissionsEx] - does that mean the plugin has a dependency on PEX?

    Regards
    Souterain
    Server soutcraft.nn.pe

  • _ForgeUser10818040 added the tags New Other Jan 26, 2014
  • _ForgeUser7258426 posted a comment Jan 30, 2014

    Hi, ill have a look into it. thanks for telling me

    Also no, softdepend just means Admin360 will load after any plugin listed in SoftDepend. So it doesn't need PermissionsEx to work

  • _ForgeUser7258426 removed a tag New Jan 30, 2014
  • _ForgeUser7258426 added a tag Accepted Jan 30, 2014
  • _ForgeUser7258426 posted a comment Jan 30, 2014

    Hey buddy, thanks for the bug report again. I have uploaded a new version which i believe should fix the bug.

  • _ForgeUser10818040 posted a comment Jan 31, 2014

    Many thanks. Will update the plugin on the server, and see if the players can break anything else :)


To post a comment, please login or register a new account.