Download & Extend

Moderators can use "Account Types" to become admins

Project:Account Types
Version:5.x-1.1
Component:Code
Category:bug report
Priority:normal
Assigned:sza
Status:closed (fixed)

Issue Summary

Users who has access to user module for administer users can simply modify account type of ANY user without limit. Even if they can't "view accounttypes" in accounttypes module.

Comments

#1

You're talking about the user_edit form, right? Looks like I need to change the permission from "administer users" to "administer access control". Thanks.

#2

Status:active» fixed

Fixed it. Will be in next upload.

#3

You're talking about the user_edit form, right?

Yes.

Fixed it. Will be in next upload.

Ok.

#4

Status:fixed» closed (fixed)
nobody click here