Hikashop fresh installation can't save

  • Posts: 1057
  • Thank you received: 11
  • Hikashop Business
5 years 9 months ago #303786

-- HikaShop version -- : 4.0.2
-- Joomla version -- : 3.9.3
-- PHP version -- : 7.2

Hello!

I installed Hikashop latest version, and when i click "save" in configuration page, the page crashed and i got the error:
"Forbidden
You don't have permission to access /new/administrator/index.php on this server.
Additionally, a 403 Forbidden error was encountered while trying to use an ErrorDocument to handle the request."

This happened in two different websites. Any idea why this happens?

Thank you in advance

Please Log in or Create an account to join the conversation.

  • Posts: 82868
  • Thank you received: 13376
  • MODERATOR
5 years 9 months ago #303791

Hi,

I don't see why that would happen. We don't have the problem and so far no one else reported the issue.
Which version did you have before the update ?
Also, could it be a security extension you have on both websites which would generate a false positive ?
Did you find a similar issue elsewhere in the backend of HikaShop ?

Please Log in or Create an account to join the conversation.

  • Posts: 1057
  • Thank you received: 11
  • Hikashop Business
5 years 9 months ago #303801

Request: POST /new/administrator/index.php?option=com_hikashop&ctrl=config
Action Description: Access denied with code 403 (phase 2).
Justification: Pattern match "<\\?(?!xml\\s)" at ARGS:config_address_format.

Maybe its a false one by modsecurity. Is it? If yes i can disable that rule

SecRule ARGS|ARGS_NAMES|REQUEST_COOKIES|REQUEST_COOKIES_NAMES|XML:/*|!ARGS:/body/|!ARGS:/content/|!ARGS:/description/|!ARGS:/message/|!ARGS:optionsQuery|!ARGS:Post|!ARGS:desc|!ARGS:text|!REQUEST_COOKIES:/__utm/|!REQUEST_COOKIES:/_pk_ref/ "<\?(?!xml\s)" \
"id:211220,msg:'COMODO WAF: PHP Injection Attack||%{tx.domain}|%{tx.mode}|2',phase:2,capture,block,setvar:'tx.points=+%{tx.points_limit4}',ctl:auditLogParts=+E,t:none,t:htmlEntityDecode,t:compressWhitespace,t:lowercase,rev:3,severity:2,tag:'CWAF',tag:'Generic'"

Please Log in or Create an account to join the conversation.

  • Posts: 26158
  • Thank you received: 4028
  • MODERATOR
5 years 9 months ago #303802

Hello,

The configuration include the setting for the address template which is a PHP file ; so yes it submit content with the " <?php " content.
Please note that with the restriction, you won't be able to save or create view override neither.

Regards,


Jerome - Obsidev.com
HikaMarket & HikaSerial developer / HikaShop core dev team.

Also helping the HikaShop support team when having some time or couldn't sleep.
By the way, do not send me private message, use the "contact us" form instead.

Please Log in or Create an account to join the conversation.

  • Posts: 1057
  • Thank you received: 11
  • Hikashop Business
5 years 9 months ago #303815

So is it ok if I disable the rule? (modsec rule)

Please Log in or Create an account to join the conversation.

  • Posts: 82868
  • Thank you received: 13376
  • MODERATOR
5 years 9 months ago #303818

Yes, you can disable that rule.

The following user(s) said Thank You: verzevoul

Please Log in or Create an account to join the conversation.

Time to create page: 0.061 seconds
Powered by Kunena Forum