Uploaded image for project: 'CiviCRM'
  1. CiviCRM
  2. CRM-1699

Access control breach in "My Contact Dashboard"

    Details

    • Type: Bug
    • Status: Done/Fixed
    • Priority: Major
    • Resolution: Fixed/Completed
    • Affects Version/s: 1.7
    • Fix Version/s: 1.7
    • Component/s: Core CiviCRM
    • Labels:
      None

      Description

      Case:

      1. Go to http://dgg.qdev.civicrm.org/
      2. Log in as demo2:demo2
      3. Go to "My Contact Dashboard" (http://dgg.qdev.civicrm.org/index.php?q=civicrm/user&reset=1) - you should see a screen with no group memberships
      4. In "Join a Group" pull down you should see 3 groups (all of them are public groups)
      5. Add yourself to "Advisory Board" group
      6. After the screen reloads, you will see two additional groups in "Join a Group" pull down (in addition to 2 remaing public groups), which is a bug (those are "User and User Admin Only" groups!)
      7. Add yourself to "Administrators" group (normally, you shouldn't be able to do this!)

        Attachments

          Activity

            People

            • Assignee:
              yashodha Yashodha Chaku
              Reporter:
              mover Michał Mach
            • Votes:
              0 Vote for this issue
              Watchers:
              0 Start watching this issue

              Dates

              • Created:
                Updated:
                Resolved: