Bug #15908
closed
Users with Deny Config Write privilege can change their own password
Added by Marcos M over 1 year ago.
Updated 9 months ago.
Category:
User Manager / Privileges
Plus Target Version:
25.07
Description
A user with read-only privilege and access to System > User Password Manager is able to change its own password.
- Private changed from Yes to No
- Status changed from In Progress to Feedback
- % Done changed from 0 to 100
Applied in changeset commit:a4d40f3e5852a3b8cd9ae19460cfe0d8429d32ea.
I checked the patch on 24.11, the user with RO privileges is not able to change the password.
The following input errors were detected:
Insufficient privileges to make the requested change (read only).
- Plus Target Version changed from 25.01 to 25.03
- Status changed from Feedback to Resolved
- Subject changed from Read-only users can change their own password to Users with Deny Config Write privilege can change their own password
- Plus Target Version changed from 25.03 to 25.07
Also available in: Atom
PDF