Skip to content

ModSecurity triggers 403 error on "open" query admin links #2195

@PWaddict

Description

@PWaddict

With ModSecurity installed on the server, if you go to edit any page (not homepage) and then click for example the homepage on the breadcrumb links, a 403 error will be triggered because the breadcrumb urls ending with ?open=[page ID you're clicking] to keep that parent's children pages opened on the lister.

The "open" must be renamed to something like "pages_open" to prevent false positive triggers.
I don't know if this "open" query is used on other admin areas but it should be definitely renamed everywhere.

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions