Post by ramonrodrigoss » Sat Jul 03, 2021 1:56 am

Good afternoon people,

I'm facing a hell of a problem, we configured Opencart all right, but we ran into the following error:

when we log into the OpenCart control panel, no matter what username and password we enter, it log in with the admin.

Has anyone gone through something like that? I'm looking here on the forum and I didn't find it...

Thank you so much!


Posts

Joined
Fri Jul 02, 2021 8:19 pm

Post by straightlight » Sat Jul 03, 2021 5:11 pm

OC version. Already replied via PM.

Dedication and passion goes to those who are able to push and merge a project.

Regards,
Straightlight
Programmer / Opencart Tester


Legendary Member

Posts

Joined
Mon Nov 14, 2011 11:38 pm
Location - Canada, ON

Post by paulfeakins » Mon Jul 05, 2021 7:47 pm

ramonrodrigoss wrote:
Sat Jul 03, 2021 1:56 am
when we log into the OpenCart control panel, no matter what username and password we enter, it log in with the admin.
Very strange, perhaps server level caching makes it seem like you're logged in?

Perhaps ModSecurity is blocking your login attempt but you're already logged in?

Perhaps an extension has broken it?

Perhaps you've been hacked?

Sounds like you need a developer ASAP so you could pay a developer such as ourselves or post a job in the Commercial Support Forum.

UK OpenCart Hosting | OpenCart Audits | OpenCart Support - please email info@antropy.co.uk


User avatar
Guru Member
Online

Posts

Joined
Mon Aug 22, 2011 11:01 pm
Location - London Gatwick, United Kingdom

Post by Johnathan » Mon Jul 05, 2021 8:52 pm

Compare this file in your installation against the original in the version you downloaded:

/system/library/cart/user.php

That controls the logging in within the login($username, $password) function, so someone may have put code in there so they could log in with any username and password. It may or may not have been malicious, if you've had a developer work on the site recently, but it should definitely be removed.

Image Image Image Image Image


User avatar
Administrator

Posts

Joined
Fri Dec 18, 2009 3:08 am


Post by straightlight » Mon Jul 05, 2021 9:38 pm

Use a software like Beyond Compare or Winmerge to see the differences in the codes between the same OC versions with the core files.

Dedication and passion goes to those who are able to push and merge a project.

Regards,
Straightlight
Programmer / Opencart Tester


Legendary Member

Posts

Joined
Mon Nov 14, 2011 11:38 pm
Location - Canada, ON

Post by ramonrodrigoss » Tue Jul 06, 2021 10:54 pm

Thanks everyone for the answers!

Actually, the user.php file was edited and the Login function was changed.

We replaced user.php with a newer version and the issue is resolved.

Thank you so much for everyone's help!


Posts

Joined
Fri Jul 02, 2021 8:19 pm
Who is online

Users browsing this forum: grgr, nonnedelectari and 91 guests