LimeSurvey: 5.x 848a0e18

Author Committer Branch Timestamp Parent
Gabriel Jenik GitHub 5.x 2023-07-05 13:16 5.x d0ac1c92
Changeset

Fixed issue #18356: [security] User with only user update allowed can set/remove any role to any user (#3268)

Co-authored-by: lapiudevgit devgit@lapiu.biz

mod - application/controllers/UserManagementController.php Diff File
mod - application/models/User.php Diff File
add - application/models/services/UserManager.php Diff File
mod - application/views/userManagement/partial/addrole.php Diff File
mod - application/views/userManagement/partial/editpermissions.php Diff File
add - tests/unit/models/UserManagerServiceTest.php Diff File