Admin changing User level via More Actions button
-
- FormaLms User
- Posts: 124
- Joined: Thu May 05, 2016 6:53 am
- Version: forma.lms 2.0
- Location: UK
- Contact:
Admin changing User level via More Actions button
Hi,
I found a user who had been made a Super admin by an Admin, in error.
The Admin had used the More Actions option in the Organisation chart to edit a user's password, they had ticked the New password, populated the boxes and also ticked the Level which by default is set to Super admin.
This resulted in a level change, giving a user, Super admin privileges and access to all user's details.
This was in a site running 3.01, I have tested it and it is still possible in 4.0.7.
Can this be amended in the Administrator profile settings?
See image
Cheers
Graeme
I found a user who had been made a Super admin by an Admin, in error.
The Admin had used the More Actions option in the Organisation chart to edit a user's password, they had ticked the New password, populated the boxes and also ticked the Level which by default is set to Super admin.
This resulted in a level change, giving a user, Super admin privileges and access to all user's details.
This was in a site running 3.01, I have tested it and it is still possible in 4.0.7.
Can this be amended in the Administrator profile settings?
See image
Cheers
Graeme
Re: Admin changing User level via More Actions button
Hi Graeme, it's not a bug, but I agree, an Admin should not be capable of changing levels at all, or, if needed, should not be capable of elevating levels. This is a privilege escalation vulnerability of Forma.
Per supporto GRATUITO contattatemi in privato qui
-
- FormaLms User
- Posts: 124
- Joined: Thu May 05, 2016 6:53 am
- Version: forma.lms 2.0
- Location: UK
- Contact:
Re: Admin changing User level via More Actions button
Hi,
I agree Admins have no need to change levels.
It’s also a GDPR risk which is a concern.
Graeme
I agree Admins have no need to change levels.
It’s also a GDPR risk which is a concern.
Graeme
Re: Admin changing User level via More Actions button
Hello,
got it, we'll get back with a fix asap
got it, we'll get back with a fix asap
---------------------
Massimiliano Ferrari
Elearnit - Elearning e Knowledge Management
https://www.elearnit.net
https://www.linkedin.com/in/massimilianoferrari
m.ferrari[at]elearnit.net
Skype: m_ferrari_it
Massimiliano Ferrari
Elearnit - Elearning e Knowledge Management
https://www.elearnit.net
https://www.linkedin.com/in/massimilianoferrari
m.ferrari[at]elearnit.net
Skype: m_ferrari_it
-
- FormaLms User
- Posts: 124
- Joined: Thu May 05, 2016 6:53 am
- Version: forma.lms 2.0
- Location: UK
- Contact:
Re: Admin changing User level via More Actions button
Hi Max,
Thank you.
Cheers
Graeme
Thank you.
Cheers
Graeme
-
- Newbie
- Posts: 22
- Joined: Tue Feb 27, 2024 9:55 am
Re: Admin changing User level via More Actions button
Hi Graeme,
thanks for reporting and I inform you that we have released version 4.0.9 in which the problem has been resolved.
Greetings
thanks for reporting and I inform you that we have released version 4.0.9 in which the problem has been resolved.
Greetings