Announcement

#1 2021-01-22 23:57:32

SFphil
Member
2021-01-22
2

"Configuration", "General" tab showing "403 Forbidden Access" v11.1.0

Hi:

I just installed v11 using the manual method (download ZIP, extract files from ZIP, use Filezilla to copy the files to the server, setup the database, etc.).   Everything is working great - thank you for all your hard work for the v11 update!!!

HOWEVER, on the "Configuration" screen, "General" tab I get error "403 Forbidden Access to this resource on the server is denied!" when I click the "Save Settings" button.

I am able to successfully save changes on the "Configuration > Display" and "Configuration > Comments" tabs.  I'm also able to upload new images.

I reviewed some other FORUM postings on this "403 Forbidden" error but I don't think it's a security problem on "_data", "local" or "upload" folders because I see lots of files being modified in those folders.

Piwigo version: 11.1.0
Apache Version    2.4.46
PHP Version    7.4.11
MySQL Version    10.3.27-MariaDB

Offline

 

#2 2021-01-27 03:48:25

wawii
Member
2021-01-27
3

Re: "Configuration", "General" tab showing "403 Forbidden Access" v11.1.0

Just installed Piwigo, and am having the same issues when trying to save Configuration Options (Piwigo configuration [General]).



Forbidden
You don't have permission to access this resource.

Additionally, a 403 Forbidden error was encountered while trying to use an ErrorDocument to handle the request.



Piwigo 11.1
PHP version: 7.3.6
MySQL version: 5.7.33
cpsrvd 11.92.0.9
Database client version: libmysql - 5.6.43

Last edited by wawii (2021-01-27 03:49:21)

Offline

 

#3 2021-01-28 01:42:10

wawii
Member
2021-01-27
3

Re: "Configuration", "General" tab showing "403 Forbidden Access" v11.1.0

Found a work around:
I was able to update the settings that I needed to update by directly editing the contents of table piwi0v_config via phpmyadmin.

https://piwigo.org/forum/viewtopic.php? … 72#p173172

Offline

 

#4 2021-01-28 10:58:41

plg
Piwigo Team
Nantes, France, Europe
2002-04-05
13564

Re: "Configuration", "General" tab showing "403 Forbidden Access" v11.1.0

OK, so the problem is modSecurity. I really wonder why there is such a specific issue with this page :-/

Offline

 

#5 2021-01-28 15:58:21

wawii
Member
2021-01-27
3

Re: "Configuration", "General" tab showing "403 Forbidden Access" v11.1.0

Not sure, I was also able to turn off modSecurity, and with it off also make the configuration chnages.

Offline

 

#6 2021-02-08 08:09:24

cryopad
Piwigo Team
Grenoble, France
2015-11-01
165

Re: "Configuration", "General" tab showing "403 Forbidden Access" v11.1.0

@wawii,
Can you please activate the debug mode of modSecurity and look for the false positive detection leading to the reject of the Configuration / General page? For example: https://resources.infosecinstitute.com/ … rity-logs/


If you enjoy Piwigo for iOS…
➤ We would appreciate an AppStore review.
➤ Comments, suggestions ? Tell us on GitHub…
➤ Not yet available in your language ? Help us translate it…

Offline

 

#7 2021-05-19 22:52:15

profi
Member
2021-05-17
2

Re: "Configuration", "General" tab showing "403 Forbidden Access" v11.1.0

Hello,
has someone found a solution to this problem?
Obviously, it's actually a modsecurity problem.
Unfortunately, my knowledge in this regard is not really sufficient to adequately isolate the error.
However, I am obviously not the only candidate with this problem - by the way, I have 2 applications.
Current version of Piwigo!
I am thankful for every hint!

Offline

 

#8 2022-02-04 22:50:43

musasoyyo
Member
2022-02-04
1

Re: "Configuration", "General" tab showing "403 Forbidden Access" v11.1.0

I tried deactivating ModSecurity and now I'm able to make the changes in the setting page, I then reactivated ModSecurity.

Offline

 

Board footer

Powered by FluxBB

github twitter newsletter Donate Piwigo.org © 2002-2022 · Contact