View Issue Details

IDProjectCategoryView StatusLast Update
0007466mantisbtsecuritypublic2007-05-08 03:43
Reportervboctor Assigned Tovboctor  
PrioritynormalSeveritymajorReproducibilityalways
Status closedResolutionfixed 
Product Version1.0.5 
Fixed in Version1.0.6 
Summary0007466: Port: 6719: Manager of a project can assign the Administrator role to a user.
Description

A manager should not be able to assign a role higher than manager to a user on any of his projects. When a user is assigned the Administrator role on a project, he can delete and create users, he can delete and create custom fields, he can change the system configuration. This is a major flaw in the security of MANTIS. The simpler way to fix this is to remove the ability to pick administrator as a role from a manager.

TagsNo tags attached.

Relationships

related to 0006719 closedvboctor Manager of a project can assign the Administrator role to a user. 

Activities

There are no notes attached to this issue.