[Vtigercrm-developers] vtiger Marketplace Extension killed entire vtiger system!

Alan Lord alanslists at gmail.com
Tue Feb 10 11:07:40 GMT 2015


One of our customers has purchased a couple of Extensions via the 
Extension Store.

One of these modules didn't work with our vtlib created entity modules 
so they contacted the vendor who, after a while, emailed them a new 
version of the module as a zip package; one for php5.3 and one for 
php5.4 (odd why the distinction but I didn't think much of it at the 
time)...

My customer asked me for help to install this module. I said their 
server ran php5.3 and to use the "Install from file" link in the module 
manager.

On installation the module crashed their entire vtiger system; not 
allowing them to login or view any screens.

The error message sent to the screen was:

> Site error: the file /var/www/vtigerCRM/modules/BoruDragDropDoc/models/Module.php requires the ionCube PHP Loader ioncube_loader_lin_5.3.so to be installed by the website operator. If you are the website operator please use the ionCube Loader Wizard to assist with installation.

Should one module be able to do this?

(I had to manually edit the vtiger_tab file and disable the module so 
they could log in and use the system again.)

Al

PS: I would suggest that there is a statement on the Marketplace about 
encrypted extensions. The user, and the vtiger marketplace verification 
process presumably, will have no idea what these extensions could be 
doing in the background (calling home, copying data...)



More information about the vtigercrm-developers mailing list