View Issue Details
ID | Project | Category | View Status | Date Submitted | Last Update |
---|---|---|---|---|---|
19414 | Bug reports | User / Groups / Roles | public | 2024-02-13 16:21 | 2024-10-16 20:07 |
Reporter | DenisChenu | Assigned To | |||
Priority | none | Severity | minor | ||
Status | new | Resolution | open | ||
Product Version | 5.6.x | ||||
Summary | 19414: Roles management : No way to assign minimal roles by «admin user» | ||||
Description | Since fix https://bugs.limesurvey.org/view.php?id=18977 (18977: Improper Authorization in add role function leads to privilege escalation) | ||||
Steps To Reproduce | Steps to reproduceCreate role with "Create survey" + "Use theme"
As this user : create an user and try to give the role 'SurveyCreator' Expected resultThe user can give this roles Actual resultNo way to give this roles | ||||
Tags | No tags attached. | ||||
Bug heat | 16 | ||||
Complete LimeSurvey version number (& build) | 6.4.6 | ||||
I will donate to the project if issue is resolved | No | ||||
Browser | not relevant | ||||
Database type & version | not relevant | ||||
Server OS (if known) | not relevant | ||||
Webserver software & version (if known) | not relevant | ||||
PHP Version | not relevant | ||||
An idea to correct this situation would be to have an additional option on roles: who can assign or delete this role. with:
This settings can be only updated by superadmin/write permssion user. And only such user can update roles. |
|
Ping @tibor.pacalat : can you ask if such solution can be accepted in 5.X ? |
|
Date Modified | Username | Field | Change |
---|---|---|---|
2024-02-13 16:21 | DenisChenu | New Issue | |
2024-02-13 16:24 | DenisChenu | Note Added: 79476 | |
2024-02-13 16:24 | DenisChenu | Bug heat | 0 => 2 |
2024-02-13 16:25 | DenisChenu | Note Added: 79477 | |
2024-07-01 09:17 | DenisChenu | Summary | No way to assign minimal roles by «admin user» => Roles management : No way to assign minimal roles by «admin user» |
2024-10-16 20:07 | stevelegare | Issue Monitored: stevelegare | |
2024-10-16 20:07 | stevelegare | Bug heat | 2 => 10 |
2024-10-24 11:48 | sampnot12 | Bug heat | 10 => 16 |