Skip Navigation

[Resolved] Changing user_id in url, is giving acces to edit another user details.

This support ticket is created 5 years, 4 months ago. There's a good chance that you are reading advice that it now obsolete.

This is the technical support forum for Toolset - a suite of plugins for developing WordPress sites without writing PHP.

Everyone can read this forum, but only Toolset clients can post in it. Toolset support works 6 days per week, 19 hours per day.

Sun Mon Tue Wed Thu Fri Sat
- 10:00 – 13:00 10:00 – 13:00 10:00 – 13:00 10:00 – 13:00 10:00 – 13:00 -
- 14:00 – 18:00 14:00 – 18:00 14:00 – 18:00 14:00 – 18:00 14:00 – 18:00 -

Supporter timezone: Asia/Kolkata (GMT+05:30)

This topic contains 7 replies, has 2 voices.

Last updated by Minesh 5 years, 4 months ago.

Assisted by: Minesh.

Author
Posts
#1303625

Hi,
I created a user form for changing e-mail address, but I'm able to see and change e-mail address of another user when I just change user_id in url.
/account/?layout_id=71&user_id=7
/account/?layout_id=71&user_id=8
/account/?layout_id=71&user_id=9

#1303691

Minesh
Supporter

Languages: English (English )

Timezone: Asia/Kolkata (GMT+05:30)

Hello. Thank you for contacting the Toolset support.

As I understand - you created Edit user form, correct? If yes, using what role you are editing the user form? How you setup the edit form?

Could you please send me debug information that will help us to investigate your issue.
=> https://toolset.com/faq/provide-debug-information-faster-support/

#1303985
toolset_url_user_id.png

Yes, edit user form.
Role is author.
Look on my screen record here:
hidden link

#1304623

Minesh
Supporter

Languages: English (English )

Timezone: Asia/Kolkata (GMT+05:30)

I would like to confirm here - do you want to list all users with Edit user form link or only user who is logged-in?

#1304887

Only user who is logged-in.
This is "my account" changing e-mail form.
But if logged-in user with author role, can change e-mails of another author user just with change user_id in url, it mean that something is wrong.

#1305149

Minesh
Supporter

Languages: English (English )

Timezone: Asia/Kolkata (GMT+05:30)

Can you please share problem URL and admin + author user (both) access deteails.

I have set the next reply to private which means only you and I have access to it.

#1306329

It is on localhost now. I'll let you know when I put this online.

#1306403

Minesh
Supporter

Languages: English (English )

Timezone: Asia/Kolkata (GMT+05:30)

ok fine. Please update us when you setup a test site.

I have set the next reply to private which means only you and I have access to it.