Pages: 1
Hi:
I just installed v11 using the manual method (download ZIP, extract files from ZIP, use Filezilla to copy the files to the server, setup the database, etc.). Everything is working great - thank you for all your hard work for the v11 update!!!
HOWEVER, on the "Configuration" screen, "General" tab I get error "403 Forbidden Access to this resource on the server is denied!" when I click the "Save Settings" button.
I am able to successfully save changes on the "Configuration > Display" and "Configuration > Comments" tabs. I'm also able to upload new images.
I reviewed some other FORUM postings on this "403 Forbidden" error but I don't think it's a security problem on "_data", "local" or "upload" folders because I see lots of files being modified in those folders.
Piwigo version: 11.1.0
Apache Version 2.4.46
PHP Version 7.4.11
MySQL Version 10.3.27-MariaDB
Offline
Just installed Piwigo, and am having the same issues when trying to save Configuration Options (Piwigo configuration [General]).
Forbidden
You don't have permission to access this resource.
Additionally, a 403 Forbidden error was encountered while trying to use an ErrorDocument to handle the request.
Piwigo 11.1
PHP version: 7.3.6
MySQL version: 5.7.33
cpsrvd 11.92.0.9
Database client version: libmysql - 5.6.43
Last edited by wawii (2021-01-27 03:49:21)
Offline
Found a work around:
I was able to update the settings that I needed to update by directly editing the contents of table piwi0v_config via phpmyadmin.
https://piwigo.org/forum/viewtopic.php? … 72#p173172
Offline
OK, so the problem is modSecurity. I really wonder why there is such a specific issue with this page :-/
Offline
Not sure, I was also able to turn off modSecurity, and with it off also make the configuration chnages.
Offline
@wawii,
Can you please activate the debug mode of modSecurity and look for the false positive detection leading to the reject of the Configuration / General page? For example: https://resources.infosecinstitute.com/ … rity-logs/
Offline
Hello,
has someone found a solution to this problem?
Obviously, it's actually a modsecurity problem.
Unfortunately, my knowledge in this regard is not really sufficient to adequately isolate the error.
However, I am obviously not the only candidate with this problem - by the way, I have 2 applications.
Current version of Piwigo!
I am thankful for every hint!
Offline
I tried deactivating ModSecurity and now I'm able to make the changes in the setting page, I then reactivated ModSecurity.
Offline
Pages: 1