Skip to:
Content

bbPress.org

Opened 15 years ago

Closed 15 years ago

Last modified 2 years ago

#1368 closed defect (bug) (fixed)

Moderator can create users with higher permissions.

Reported by: amistad18's profile amistad18 Owned by:
Milestone: 1.1 Priority: highest omg sweet tea
Severity: blocker Version: 1.1-alpha
Component: General - Administration Keywords:
Cc:

Description

I work with - bbPress 1.1-alpha-2539, and as a moderator, i create new user with keymaster permissions, and so, I can login on that account and change the role other keymasters, administrators and moderators to common user ...

It is not safe, to add moderator that permissions, in other case, why other roles exist, if moderator can do everything, after he/she make a new account?

Change History (2)

#1 @GautamGupta
15 years ago

  • Keywords permissions removed
  • Priority changed from normal to highest
  • Severity changed from major to blocker

#2 @johnjamesjacoby
15 years ago

  • Resolution set to fixed
  • Status changed from new to closed

(In [2797]) Correct cap on Add User admin menu, and add cap check to submenus. Fixes #1368

Note: See TracTickets for help on using tickets.