Page 1 of 1

blocked by security settings

Posted: Fri 9. Dec 2022, 09:54
by hekla
When saving a template I got an error "Forbidden. You don't have permission to access this resource".

The sysadmin tells me that the security settings issue the following messages:

[msg "XSS Attack Detected via libinjection"]
[msg "Restricted File Access Attempt"]
[msg "NoScript XSS InjectionChecker: HTML Injection"]
[msg "Detects concatenated basic SQL injection and SQLLFI attempts"]
[msg "Detects MSSQL code execution and information gathering attempts"]
[msg "SQL Injection Attack Detected via libinjection"]

Can this be? and is it safe to deactivate them?

(used version: 1.8.7 )

Re: blocked by security settings

Posted: Fri 9. Dec 2022, 21:18
by Oliver Georgi
Hard to tell what exactly triggers the messages for you. Client side, server side. It has nothing to do with phpwcms at first. Only your sysadmin can tell you how more details.