Hi, overnight I've received a filled in admin form which looked suspicious as well as it was filled in at a time that no user should be online. So I have a couple questions. Can non-users submit a admin contact form? And if not, how can I see which user submitted the form? As it only shows a emailaddress in the submitted form and not a potential user that has submitted it.
I've switched off the admin form now so it can't happen again. But I'm curious to see if one of the user accounts is compromised or if it's a general contact form that can be used from the account creation page.
Thanks.
You don't. The form can be submitted by non-users, and is intended for things like "I can't get in" (so you don't know who they are because they are not logged in). You have to work from the email address.
Thanks for the quick reply. Do you know how I can determine the URL to the form to check if it is still functional?
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.
From a test with my cloud site the URL looks as follows:
https://examplesitexyz.atlassian.net/secure/ContactAdministrators!default.jspa
Please replace the example site name with your own.
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.