Problem XSS with mod_security

1 week 1 day ago #77443 by Pitou
Hello

First of all, thank you for flexicontent. So usefull.

My host has just upgraded to latest mod_security version and I'm facing some troubles with that configuration.

I've just made a test with a new article : creating, editing, adding a file : there is no problems, no alerts. I've did it several times
But with a lot of old articles that I have to edit, I've got the 403 error with mod_security.

Can you watch the logs that I'm not able to understand and tell me what kind of problem is that ?
Thank you very much.
Attachments:

Please Log in or Create an account to join the conversation.

1 week 1 day ago #77445 by ggppdk
Hello

i think you could ask your webhost about apache logs

you can see file locations of the audit_log here
also for case of cpanel, the logs could be empty and stored in DB

forums.cpanel.net/threads/mod-security-l...e-where-is-it.65656/


-- Flexicontent is Free but involves a big effort on our part.
Like the our support? (for a bug-free FC, despite having a long list of functions) Like the features? Like the ongoing development and future commitment to FLEXIcontent?
-- Add your voice to the FLEXIcontent JED listing with a 5-star review. Thanks!

Please Log in or Create an account to join the conversation.

1 week 1 day ago #77446 by Pitou
Replied by Pitou on topic Problem XSS with mod_security
Thank you GGPPDK.

Just to be clear, have you seen the logs in attachment to my first post ?

then, if flexi is not in charge, I've just be informed that our version of CRS wasn't up to date.
I'll ask to my host to upgrade, maybe it will be solved after that.

have a good evening.

Please Log in or Create an account to join the conversation.

1 week 7 hours ago #77448 by ggppdk
Hello

i miss them,
i did not see that you had attachments

i will have a look at them


-- Flexicontent is Free but involves a big effort on our part.
Like the our support? (for a bug-free FC, despite having a long list of functions) Like the features? Like the ongoing development and future commitment to FLEXIcontent?
-- Add your voice to the FLEXIcontent JED listing with a 5-star review. Thanks!

Please Log in or Create an account to join the conversation.

Moderators: vistamediajoomlacornerggppdk
© 2018 Flexicontent. All Rights Reserved.