Security issues » History » Revision 3
2010-09-29 - High risk - Course directory removal risk through tasks tool¶
At around 11:55, Belgian time, on 29/09/2010, a new security issue has been reported by user mdube on the Chamilo forum1.
- Risk level: high
- Versions affected: 126.96.36.199, 1.8.7, 188.8.131.52
- Triggered by: teachers and administrators (no anonymous/student access)
- Patch: See link  below
This security issue's risk level is considered high (on a scale of critical, high, moderate and low) in the sense you require edition permissions in the course to provoke it (relatively safe) but it provokes highly painful damages: it deletes a course directory, entirely.
This bug affects versions 184.108.40.206, 1.8.7 and 220.127.116.11.
For previous versions of Chamilo, you will have to look at the patch and apply the differences manually.
The problem can be reproduced by trying to delete an un-existing student work from a course. The delete URL can be crafted manually, but it can also be triggered by a double click on the delete icon for a student work.
This means that if you have teachers accidentally double-clicking on the delete icon, they can delete the entire course directory. The only solution then is to restore the course directory quickly from your daily backup.
This bug was introduced in November of 20094, while still working on Dok€os, by a then member of the BeezNest team trying to fix a complex issue by using the permanently_remove_deleted_files parameter to decide whether to delete the files permanently or to leave them on disk. This flaw could apply to Dok€os 2.0 (cannot be checked until the code is made available). The developer doesn't work with us anymore, and we have considerably improved the review process, but this specific kind of bug implies a peer review process, and this can only come with regular investment.
Using the services of an official Chamilo provider5 guarantees your contributions go to Chamilo and help many other organizations and people around the world, just as
you benefit from contributions from many others. Contribute to the Chamilo project using our official providers services and encourage our healthy and socially responsible economical model!
Lead developer for Chamilo 1.8