[Vtigercrm-commits] [Vtiger development] #7714: Any user can change any field data on other user (except for the password), Even eliminate the admin privileges to the user Admin

Vtiger development vtiger-tickets at trac.vtiger.com
Fri Aug 1 09:02:00 GMT 2014


#7714: Any user can change any field data on other user (except for the password),
Even eliminate the admin privileges to the user Admin
----------------------------------+--------------------------
 Reporter:  juanpablojp1          |       Owner:  developer
     Type:  defect                |      Status:  new
 Priority:  critical              |   Milestone:  6.1.0
Component:  vtigercrm             |     Version:  6.1.0 - wip
 Severity:  Medium                |  Resolution:
 Keywords:  privilege escalation  |
----------------------------------+--------------------------

Comment (by joebordes):

 Proposed solution for vtigercrm 5.4.0:
 http://corebos.org/development/view.php?id=215

--
Ticket URL: <http://trac.vtiger.com/cgi-bin/trac.cgi/ticket/7714#comment:5>
Vtiger development <http://trac.vtiger.com/>
Vtiger CRM


More information about the vtigercrm-commits mailing list