Moderators can use "Account Types" to become admins
sza - August 20, 2007 - 16:07
| Project: | Account Types |
| Version: | 5.x-1.1 |
| Component: | Code |
| Category: | bug report |
| Priority: | normal |
| Assigned: | sza |
| Status: | closed |
Jump to:
Description
Users who has access to user module for administer users can simply modify account type of ANY user without limit. Even if they can't "view accounttypes" in accounttypes module.

#1
You're talking about the user_edit form, right? Looks like I need to change the permission from "administer users" to "administer access control". Thanks.
#2
Fixed it. Will be in next upload.
#3
Yes.
Ok.
#4