Skip to main content

This site requires you to update your browser. Your browsing experience maybe affected by not having the most up to date version.

General Questions /

General questions about getting started with SilverStripe that don't fit in any of the categories above.

Moderators: martimiz, Sean, biapar, Willr, Ingo, swaiba, simon_w

[BUG?] 2.4.6 - Avoid privilege escalation


Reply


2 Posts   486 Views

Avatar
nekranox

Community Member, 31 Posts

27 February 2012 at 11:43pm

Hey guys,

Is this a bug or am I just being noob?

In 2.4.7 when logging in as the default admin I am unable to assign users to the Administrators group. I checked the changelog and in 2.4.6 found the follow commit: https://github.com/silverstripe/sapphire/commit/de1f070

By commenting out this function I was able to assign the accounts I had created to the administrator group using the default admin account.

Is the default admin user not being properly assigned to the admin group? Thus the function is denying onChangeGroups()? Or am I just being noob?

Robbie

Avatar
borriej

Community Member, 267 Posts

28 February 2012 at 4:14am

im having the same problem! needed to go into phpMyAdmin to set a secondary admin manually! Please fix..