Project

General

Profile

Actions

Bug #99715

closed

non-admin user might access "admin-only" module

Added by Oliver Bartsch almost 2 years ago. Updated almost 2 years ago.

Status:
Closed
Priority:
Should have
Category:
Miscellaneous
Target version:
-
Start date:
2023-01-25
Due date:
% Done:

100%

Estimated time:
TYPO3 Version:
12
PHP Version:
Tags:
Complexity:
Is Regression:
Sprint Focus:

Description

A non-admin user might be able to access "admin-only" modules in case the users' groupData still contain the module. This however can only happen in case an admin filesystem access manually adjusted the module configuration by changing access to "user", allowed module access for the user / user group and afterwards reverted the change in the module configuration.

Actions

Also available in: Atom PDF