Print Page | Close Window

Edit Profile (pop_editprofile.asp)

Printed From: Web Wiz Forums
Category: Web Wiz Web App Support Forums
Forum Name: Web Wiz Forums
Forum Description: Support forum for Web Wiz Forums application.
URL: https://forums.webwiz.net/forum_posts.asp?TID=4323
Printed Date: 02 April 2026 at 10:48pm
Software Version: Web Wiz Forums 12.08 - https://www.webwizforums.com


Topic: Edit Profile (pop_editprofile.asp)
Posted By: Mikeap
Subject: Edit Profile (pop_editprofile.asp)
Date Posted: 18 July 2003 at 10:50am

I am not sure if this a problem with the code or whether or not my usergroups are messed up but here goes.

No matter who is logged in, no matter what usergroup, if a user goes into a post, clicks the "PROFILE" button under the post he can see the "EDIT PROFILE" button and of course this allows him to change any information about the person.  It's nice that he can't change their password but all the information non-the-less.

I've tried to change the IF statement around the button and nothing seems to work.  I am about to remove the button all together.

Has anyone else had this problem?



-------------
I am dedicated to being addicted.



Replies:
Posted By: huwnet
Date Posted: 18 July 2003 at 12:33pm
Usally only an administrator or Moderator can click edit profile. If any users can then your files are corrupted!

Huw


Posted By: Arowen
Date Posted: 13 August 2003 at 7:41pm
I have this problem with the version 7.01 at our site as well.. Was discovered just today... I hope that someone may have a fix for it...


Posted By: WebWiz-Bruce
Date Posted: 14 August 2003 at 1:11am

Unless you have set moderator permissions on the group then this is not possible unless you have corrupted files.

Check your group permissions setup for all your groups and make sure that only the modertor group (which only people you set as modertors should be part of) has moderator permissions. Also check the set up of the generic permissions themselves.



-------------
https://www.webwiz.net/web-wiz-forums/forum-hosting.htm" rel="nofollow - Web Wiz Forums Hosting
https://www.webwiz.net/web-hosting/windows-web-hosting.htm" rel="nofollow - ASP.NET Web Hosting


Posted By: jamwiz
Date Posted: 02 September 2003 at 4:18pm

Hello,

I think there is a serious problem in the pop_profile_edit.asp around line 384.

The line:

If ((blnAdmin) OR (blnModerator AND intUsersGroupID <> 1)) Then

should be

If blnAdmin Then

This should fix the problem.

If the OR condition is assumed to be OK, then there must be something else broken before getting to this point in the code.

Jamal

Originally posted by -boRg- -boRg- wrote:

Unless you have set moderator permissions on the group then this is not possible unless you have corrupted files.

Check your group permissions setup for all your groups and make sure that only the modertor group (which only people you set as modertors should be part of) has moderator permissions. Also check the set up of the generic permissions themselves.



Posted By: dead_angel
Date Posted: 02 September 2003 at 5:34pm

that line is obviously used by all webwiz users.. and so should not really cause you any problem as it is used fine by others..

OR (blnModerator AND intUsersGroupID <> 1))  is used to allow MODERATORS permission to edit the profile is it not? so you need that piece of code..

again, like the others have said, you either have corrupt files (try reuploading them) or your permissions are set incorrect..



Posted By: jamwiz
Date Posted: 02 September 2003 at 10:14pm

Hello,

I know for sure the files are not corrupted. I just started this webwiz forum and I haved converted the database to Access 2002 fromat to see what happens, but without luck.

I don't know if this has any effect, but I created a private group which has no moderation status, but still any member edit the others' profiles, of course if I did not make modification in the code.  Just like the others, as an Admin, I did not know about until a user informed me about it. I just can't believe that all the others who posted about the same problem have corruption in their databases. I'll dig thru the asp code and I'll see to find the cause, but there is definitly a problem.

Jamal

Originally posted by dead_angel dead_angel wrote:

that line is obviously used by all webwiz users.. and so should not really cause you any problem as it is used fine by others..

OR (blnModerator AND intUsersGroupID <> 1))  is used to allow MODERATORS permission to edit the profile is it not? so you need that piece of code..

again, like the others have said, you either have corrupt files (try reuploading them) or your permissions are set incorrect..



Posted By: b_bonnett
Date Posted: 02 September 2003 at 10:59pm

Well, its obviously something to do with your server, as the majority of people (myself included) have no problem whatsoever with that code - only the people who are allowed to (admin and moderators) can edit a users profile.

Blair



-------------
Webmaster, http://www.planegallery.net/ - The Plane Gallery
Greetings From Christchurch


Posted By: MadDog
Date Posted: 02 September 2003 at 11:22pm
i had this problem before. Open up the database and look at the tblPermissions table.

Make the field "Moderate" is not checked on any of the groups (or members) that you dont want to moderator the forum.

-------------
http://www.iportalx.net" rel="nofollow">


Posted By: WebWiz-Bruce
Date Posted: 03 September 2003 at 2:14am

It is certainly a permisisons problem, if a member has moderator previlliges in any forum or if there user group has moderator permissions then they will beable to change others profiles.

Check your permisisons on all forums and groups very carefully as it would appear you have gevin moderator permisisons to the erong group.



-------------
https://www.webwiz.net/web-wiz-forums/forum-hosting.htm" rel="nofollow - Web Wiz Forums Hosting
https://www.webwiz.net/web-hosting/windows-web-hosting.htm" rel="nofollow - ASP.NET Web Hosting


Posted By: jamwiz
Date Posted: 03 September 2003 at 10:47am

Hello,

Yes, one group had a Moderator permission but it was only for a specific forum not the other forums which are not moderated but the user were allowed to Edit Profiles on any forum they access to!! I think that should not occur and it's a design issue that could cause security problems.

Anyway, great forum and keep the great work.

Jamal

Originally posted by -boRg- -boRg- wrote:

It is certainly a permisisons problem, if a member has moderator previlliges in any forum or if there user group has moderator permissions then they will beable to change others profiles.

Check your permisisons on all forums and groups very carefully as it would appear you have gevin moderator permisisons to the erong group.



Posted By: MadDog
Date Posted: 03 September 2003 at 10:55am
I bet you ran a database upgrade script that messed up the permissions....

-------------
http://www.iportalx.net" rel="nofollow">


Posted By: jamwiz
Date Posted: 03 September 2003 at 2:27pm

Nope! You lose the bet  I did the upgrade to Access 2002 after the fact, to see if that will help, but it did not.

Jamal

Originally posted by MadDog MadDog wrote:

I bet you ran a database upgrade script that messed up the permissions....




Print Page | Close Window

Forum Software by Web Wiz Forums® version 12.08 - https://www.webwizforums.com
Copyright ©2001-2026 Web Wiz Ltd. - https://www.webwiz.net