Security Bug – Hotlink

in Download Manager Free

Viewing 6 posts - 1 through 6 (of 6 total)
Apr 7, 2017 at 1:37 pm
#56287
Member
Rosa
OP

After i try in your site upload a file and Allow Access: Subscriver / Demo and try to download the file in guest mode with the default url:
https://demo.wpdownloadmanager.com/wpdmpro/wpdm-package/sadasdasd/

Everthing is ok and askme to login, but if one user have access to this page can view to download link in html and share this and everyone can download, even i protect with restritc Allow Acess:
https://demo.wpdownloadmanager.com/wpdmpro/wpdm-package/sadasdasd/?wpdmdl=13012

You can try this direct url (hotlink) to the file in guest mode, you download with no problems!

Apr 7, 2017 at 1:55 pm
#56290
Member
Rosa
OP

Its seems you have an option to buy one protection for this.

But the https://demo.wpdownloadmanager.com dont have this addon active?

Apr 10, 2017 at 11:51 am
#56376
Member
Rosa
OP

Any news about this?

Apr 11, 2017 at 12:37 pm
#56432
Member
Rosa
OP

Ok, now downloads a txt file saying “You don’t have permission to download this file”

Anything changed?

Apr 14, 2017 at 10:49 am
#56594
Member
Rosa
OP

7 days no answer?

I hope to buy the pro but this way i dont know 🙁

Apr 15, 2017 at 11:21 am
#56643
Keymaster
Shahjada
Staff

Nothing changed, the direct link will work for public files only, who don’t have access to that file, you will get a file with that text.

Viewing 6 posts - 1 through 6 (of 6 total)

The topic "Security Bug – Hotlink" is closed to new replies.