-
-
Notifications
You must be signed in to change notification settings - Fork 402
Error 403 when saving settings at /wp-admin/index.php?page=aioseo-setup-wizard#/category #2095
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Comments
Thank you for reporting @issuesreporting. I confirm your finding:
This call triggers rule 930120: OS File Access Attempt. |
Thank you for confirmation. Is there any sort of additional information I can support you with that may be helpful? |
Yes, your audit log reports an anomaly score of 100 in rule 949110, yet the log only brings a single alert on 930120 that in a normal installation accounts for an anomaly score of 5. Did you remove rule alerts that account for remaining anomaly score of 95? |
additionally backend log of httpd reports following
|
Thank you. But this is the expected repetition of the rule alert 949110 above. It does not say how you end up with a score of 100. Would you mind grepping for |
I would like to make a correction, I see that I wrote about backend, but in reality it was frontend log file. The line presented in previous post. As for other information - only that from modsecurity log is present. No more files of any sort, unless I'm missing something out.
|
The score is very odd, but I am quite sure it has nothing to do with CRS. As for the false positive itself, we'll look into it. But it may take a few weeks. |
I will add this to the WordPress exclusions package. |
We talked about this issue at our recent project meeting. Decision: @lifeforms will take this on and do the fix. As an addendum, we are OK with covering WP plugins in Rule Exclusion packages. |
Ping @lifeforms ... |
@lifeforms, would you like to schedule this for the chat tonight and we reassign it to somebody else? |
Sorry for the late comment, I created a PR in #2311. |
Uh oh!
There was an error while loading. Please reload this page.
path:
example.com/wp-admin/index.php?page=aioseo-setup-wizard#/category
Clicking save button causes endless animation of button without any further visual results or changes.
Log file of modsecurity reports error 403
Log file of accesslog reports error 403
Environment
CRS version (e.g., v3.2.0): 3.30
The text was updated successfully, but these errors were encountered: