- Joined
- Feb 7, 2018
- Messages
- 34
- Reaction score
- 12
I have been testing the V20 upgrade from V18. I took a recent V18 backup, 1 or 2 days prior, and restored it to a V20 trial instance ( I did not include the FQDN or License key in the V18 backup). The trial V20 instance has a different FQDN and license key from our V18 instance. The V20 instance is on a completely different network with a different internet provider. I noticed a peculiar behavior when I started testing functions. I sent a test chat message to a user. Some how the user received the message on their mobile app that was currently registered with the V18 instance. I was also able to place a call to the same user and they received the call through their mobile app(currently registered with the V18 instance). When they picked it up it just disconnected the call. It seems the restored user still had a one way "session" open to the mobile app. The chat showed up in the notifications on the phone but was missing from the chat window in the 3cx mobile app. It seems kind of like a ghost message/call. I restarted all the services along with the OS. This did not kill the one way "session". I had to reset the password on the user to kill the "session". I'm sure this is a special circumstance but it was a bit alarming when I accidentally messaged a user that was in our production environment. I'm also worried that this may be exploitable on some level.