Opened 13 years ago

Closed 13 years ago

#2237 closed defect (fixed)

Security Hole

Reported by: pieper Owned by: don
Priority: blocker Milestone: 5.0.3
Component: vtigercrm Version: 5.0.0
Severity: Keywords:
Cc:

Description

login as non admin user; afterwards change the url to: http://yourvtiger installation/index.php?action=profilePrivileges&module=Users&mode=view&parenttab=Settings&profileid=2&selected_tab=&selected_module=

You will have administrator privileges to change the profile settings!

Change History (4)

comment:1 Changed 13 years ago by mickie

  • Milestone set to 5.0.2
  • Owner changed from developer to don

comment:2 Changed 13 years ago by nithyachandar

  • Milestone changed from 5.0.2 to 5.0.3

comment:3 Changed 13 years ago by Lukas

You will have administrator privileges for all settings :|

comment:4 Changed 13 years ago by saraj

  • Resolution set to fixed
  • Status changed from new to closed
Note: See TracTickets for help on using tickets.