Skip to content

Prevent trigger errors on demand for instances that are opened to anonymous #13513

@mattab

Description

@mattab

When using a specially crafted URL, and if the Matomo instance is opened to anonymous, one can trigger error requests on demand.

URL: /index.php?module=Widgetize&action=iframe&moduleToWidgetize=CorePluginsAdmin&actionToWidgetize=safemode&idSite=1&period=week&date=yesterday&error_message=X&error_file=Y&error_line=111

Let's solve this so that it is not possible to trigger an error on demand (ie. prevent widgetise the safemode screen)

Metadata

Metadata

Assignees

Labels

BugFor errors / faults / flaws / inconsistencies etc.

Type

No type

Projects

No projects

Milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions