View Issue Details
| ID | Project | Category | View Status | Date Submitted | Last Update | 
|---|---|---|---|---|---|
| 19414 | Bug reports | User / Groups / Roles | public | 2024-02-13 16:21 | 2024-10-16 20:07 | 
| Reporter | DenisChenu | Assigned To | |||
| Priority | none | Severity | minor | ||
| Status | new | Resolution | open | ||
| Product Version | 5.6.x | ||||
| Summary | 19414: Roles management : No way to assign minimal roles by «admin user» | ||||
| Description | Since fix https://bugs.limesurvey.org/view.php?id=18977 (18977: Improper Authorization in add role function leads to privilege escalation) | ||||
| Steps To Reproduce | Steps to reproduceCreate role with "Create survey" + "Use theme" 
 As this user : create an user and try to give the role 'SurveyCreator' Expected resultThe user can give this roles Actual resultNo way to give this roles | ||||
| Tags | No tags attached. | ||||
| Bug heat | 16 | ||||
| Complete LimeSurvey version number (& build) | 6.4.6 | ||||
| I will donate to the project if issue is resolved | No | ||||
| Browser | not relevant | ||||
| Database type & version | not relevant | ||||
| Server OS (if known) | not relevant | ||||
| Webserver software & version (if known) | not relevant | ||||
| PHP Version | not relevant | ||||
| An idea to correct this situation would be to have an additional option on roles: who can assign or delete this role. with: 
 This settings can be only updated by superadmin/write permssion user. And only such user can update roles. | |
| Ping @tibor.pacalat : can you ask if such solution can be accepted in 5.X ? | |
| Date Modified | Username | Field | Change | 
|---|---|---|---|
| 2024-02-13 16:21 | DenisChenu | New Issue | |
| 2024-02-13 16:24 | DenisChenu | Note Added: 79476 | |
| 2024-02-13 16:24 | DenisChenu | Bug heat | 0 => 2 | 
| 2024-02-13 16:25 | DenisChenu | Note Added: 79477 | |
| 2024-07-01 09:17 | DenisChenu | Summary | No way to assign minimal roles by «admin user» => Roles management : No way to assign minimal roles by «admin user» | 
| 2024-10-16 20:07 | stevelegare | Issue Monitored: stevelegare | |
| 2024-10-16 20:07 | stevelegare | Bug heat | 2 => 10 | 
| 2024-10-24 11:48 | sampnot12 | Bug heat | 10 => 16 | 


