Security problem with "Mandanten" administration

Gesperrt
ojo
Beiträge: 13
Registriert: So 19. Jan 2003, 00:27
Kontaktdaten:

Security problem with "Mandanten" administration

Beitrag von ojo » Fr 4. Jul 2003, 07:39

On the Contenido 4.3.1 beta WAMP incl. demo datebase.

Defining a new site exposes a security problem using the "mandanten" administration.

1) Log onto the backend using the "sysadmin" user.
2) Define a new "Mandanten". Name it "Kunde 2"
3) Define a language "deutch" under "Kunde 2"

Remember that the standard user "admin" is defined to have administrator access ONLY to the standard site "Kunde".

Now log in as "admin" and go to " Administation | Mandanten " and click on the "Kunde 2".

The user is able to modify "Mandanten - Eigenschaften" on all "Mandanten" although the users is not defined to be able to administer anything but "Kunde".

;-) Ojo

htw
Beiträge: 490
Registriert: Sa 5. Okt 2002, 03:09
Wohnort: Hessen
Kontaktdaten:

Added

Beitrag von htw » Di 15. Jul 2003, 14:31

Problem added to BugTracker:

http://bugs.contenido.de

Gesperrt