Vanilla 1 is no longer supported or maintained. If you need a copy, you can get it here.
HackerOne users: Testing against this community violates our program's Terms of Service and will result in your bounty being denied.
Security issue: separation of privileges
I've been testing Vanilla for a few weeks now, and i found something which could be a security issue: in the Role Management, where you assign privileges to certain roles, I see two options:
"Administrative privileges for users AND roles"
"Administrative privileges for discussions AND categories"
I think that the privileges for users, roles, discussions, and categories should be separated. A real-life example: I create a role called "Moderator". I want this role to be able to modify discussions (and maybe users), but I do not want to give them access to the roles and categories configuration, for security reasons.
What do you think about this?
0
This discussion has been closed.
Comments