View Issue Details
| ID | Project | Category | View Status | Date Submitted | Last Update |
|---|---|---|---|---|---|
| 14827 | Bug reports | Security | public | 2019-04-30 11:33 | 2021-07-12 15:11 |
| Reporter | bewi | Assigned To | |||
| Priority | normal | Severity | minor | ||
| Status | closed | Resolution | fixed | ||
| Product Version | 3.17.x | ||||
| Fixed in Version | 5.x | ||||
| Summary | 14827: admin without rights can access pages | ||||
| Description | admins with limited rights (non superadmins, no access to config area) are able to access the following directories even though they were not linked anywhere in the application: The users can access the directories, but they can neither add anything to them, nor edit | ||||
| Tags | No tags attached. | ||||
| Bug heat | 254 | ||||
| Complete LimeSurvey version number (& build) | Version 3.17.1+190408 | ||||
| I will donate to the project if issue is resolved | No | ||||
| Browser | |||||
| Database type & version | * | ||||
| Server OS (if known) | |||||
| Webserver software & version (if known) | |||||
| PHP Version | * | ||||
|
access directory? I'm not sure to understand. what do you see exactly? |
|
|
ok I can reproduce (direct access to the url works, the view is displayed, even if no action on the page is possible) |
|
|
Hello bewi, c_schmitz |
|
| Date Modified | Username | Field | Change |
|---|---|---|---|
| 2019-04-30 11:33 | bewi | New Issue | |
| 2019-04-30 13:45 | c_schmitz | Assigned To | => LouisGac |
| 2019-04-30 13:45 | c_schmitz | Status | new => assigned |
| 2019-04-30 13:46 | c_schmitz | Priority | none => urgent |
| 2019-04-30 13:46 | c_schmitz | Reproducibility | have not tried => always |
| 2019-04-30 15:27 |
|
Note Added: 51702 | |
| 2019-04-30 15:30 |
|
Note Added: 51703 | |
| 2020-03-05 14:03 | cdorin | Priority | urgent => normal |
| 2020-03-05 14:03 | cdorin | Status | assigned => confirmed |
| 2021-07-12 15:11 | c_schmitz | Status | confirmed => resolved |
| 2021-07-12 15:11 | c_schmitz | Resolution | open => fixed |
| 2021-07-12 15:11 | c_schmitz | Fixed in Version | => 5.x |
| 2021-07-12 15:11 | c_schmitz | Status | resolved => closed |
| 2021-07-12 15:11 | c_schmitz | Note Added: 65381 |