Announcement

  •  » Miscellaneous
  •  » Administrator should not be able to change password of the Webmaster

#1 2016-02-12 11:30:40

Flake
Guest

Administrator should not be able to change password of the Webmaster

Hi,

right now a administrator can change the password of the webmaster in the user management interface.
With the changed password and the username he can login to webmaster account and get super-rights.

cheers
Flake

Piwigo version: 2.7.4
PHP version: 5.6.17-3
MySQL version: 5.5.5-10.0.23-MariaDB-2
Piwigo URL: not public

 

#2 2016-02-12 11:32:13

Flake
Guest

Re: Administrator should not be able to change password of the Webmaster

Maybe related [Bugtracker] ticket 3104

cheers
Flake

 

#3 2016-02-12 11:33:37

plg
Piwigo Team
Nantes, France, Europe
2002-04-05
13791

Re: Administrator should not be able to change password of the Webmaster

Hi Flake,

Good catch! we will fix it for Piwigo 2.8.

Offline

 

#4 2016-02-12 11:34:52

plg
Piwigo Team
Nantes, France, Europe
2002-04-05
13791

Re: Administrator should not be able to change password of the Webmaster

can you open an issue on https://github.com/Piwigo/Piwigo/issues ?

Offline

 

#5 2016-02-12 12:06:22

Flake
Guest

Re: Administrator should not be able to change password of the Webmaster

Github Issue
[Github] Piwigo issue #419

Thanks for the fast reply!

cheers
Flake

 
  •  » Miscellaneous
  •  » Administrator should not be able to change password of the Webmaster

Board footer

Powered by FluxBB

github twitter newsletter Donate Piwigo.org © 2002-2024 · Contact