Uploaded image for project: 'CiviCRM'
  1. CiviCRM
  2. CRM-19919

Users can edit contact even if the necessary CMS permission isn't granted

    Details

    • Type: Security Advisory
    • Status: Open
    • Priority: Minor
    • Resolution: Unresolved
    • Affects Version/s: 4.6.24
    • Fix Version/s: None
    • Component/s: None
    • Labels:
      None
    • Versioning Impact:
      None (no code merged)
    • Documentation Required?:
      None
    • Funding Source:
      Needs Funding
    • Verified?:
      No

      Description

      In testing the Dashboard feature I disabled the "edit my contact" permission for authenticated users however my test user is able to edit any relatives that are displayed in the user's dashboard even though he cannot edit his own record.
      Seemingly the edit button should not appear for his relatives just as it does not for his own records.

      See images

        Attachments

        1. 1E7at.png
          61 kB
          Yosef Romano
        2. 4ZPzG.png
          48 kB
          Yosef Romano
        3. TUDbh.png
          63 kB
          Yosef Romano
        4. UuBIH.png
          36 kB
          Yosef Romano
        5. UXzcm.png
          74 kB
          Yosef Romano

          Activity

            People

            • Assignee:
              Unassigned
              Reporter:
              yossicrm Yosef Romano
            • Votes:
              0 Vote for this issue
              Watchers:
              1 Start watching this issue

              Dates

              • Created:
                Updated: