[Koha-bugs] [Bug 23872] New: Permissions can be subverted

bugzilla-daemon at bugs.koha-community.org bugzilla-daemon at bugs.koha-community.org
Tue Oct 22 14:50:55 CEST 2019


https://bugs.koha-community.org/bugzilla3/show_bug.cgi?id=23872

            Bug ID: 23872
           Summary: Permissions can be subverted
 Change sponsored?: ---
           Product: Koha
           Version: master
          Hardware: All
                OS: All
            Status: NEW
          Severity: major
          Priority: P5 - low
         Component: Mana-kb
          Assignee: koha-bugs at lists.koha-community.org
          Reporter: martin.renvoize at ptfs-europe.com

Granular permissions for managing Mana-KB preferences were added with bug 22198
but access to those system preferences via the standard preferences page was
not locked down.. 

As such, we have a hole in the permissions logic here.

-- 
You are receiving this mail because:
You are watching all bug changes.
You are the assignee for the bug.


More information about the Koha-bugs mailing list