Hi,
I found a user who had been made a Super admin by an Admin, in error.
The Admin had used the More Actions option in the Organisation chart to edit a user's password, they had ticked the New password, populated the boxes and also ticked the Level which by default is set to Super admin.
This resulted in a level change, giving a user, Super admin privileges and access to all user's details.
This was in a site running 3.01, I have tested it and it is still possible in 4.0.7.
Can this be amended in the Administrator profile settings?
See image
Cheers
Graeme
Admin changing User level via More Actions button
Re: Admin changing User level via More Actions button
Hi Graeme, it's not a bug, but I agree, an Admin should not be capable of changing levels at all, or, if needed, should not be capable of elevating levels. This is a privilege escalation vulnerability of Forma.
Per supporto GRATUITO contattatemi in privato qui
-
- FormaLms User
- Posts: 124
- Joined: Thu May 05, 2016 6:53 am
- Version: forma.lms 2.0
- Location: UK
- Contact:
Re: Admin changing User level via More Actions button
Hi,
I agree Admins have no need to change levels.
It’s also a GDPR risk which is a concern.
Graeme
I agree Admins have no need to change levels.
It’s also a GDPR risk which is a concern.
Graeme
Re: Admin changing User level via More Actions button
Hello,
got it, we'll get back with a fix asap
got it, we'll get back with a fix asap
---------------------
Massimiliano Ferrari
Elearnit - Elearning e Knowledge Management
https://www.elearnit.net
https://www.linkedin.com/in/massimilianoferrari
m.ferrari[at]elearnit.net
Skype: m_ferrari_it
Massimiliano Ferrari
Elearnit - Elearning e Knowledge Management
https://www.elearnit.net
https://www.linkedin.com/in/massimilianoferrari
m.ferrari[at]elearnit.net
Skype: m_ferrari_it
-
- FormaLms User
- Posts: 124
- Joined: Thu May 05, 2016 6:53 am
- Version: forma.lms 2.0
- Location: UK
- Contact:
Re: Admin changing User level via More Actions button
Hi Max,
Thank you.
Cheers
Graeme
Thank you.
Cheers
Graeme
-
- Newbie
- Posts: 22
- Joined: Tue Feb 27, 2024 9:55 am
Re: Admin changing User level via More Actions button
Hi Graeme,
thanks for reporting and I inform you that we have released version 4.0.9 in which the problem has been resolved.
Greetings
thanks for reporting and I inform you that we have released version 4.0.9 in which the problem has been resolved.
Greetings