Jump to:

23374 Posts in 18175 Topics by 2866 members

General Questions

SilverStripe Forums » General Questions » [BUG?] 2.4.6 - Avoid privilege escalation

General questions about getting started with SilverStripe that don't fit in any of the categories above.

Moderators: martimiz, Sean, biapar, Willr, Ingo, swaiba, simon_w

Page: 1
Go to End
Author Topic: 365 Views
  • nekranox
    Avatar
    Community Member
    31 Posts

    [BUG?] 2.4.6 - Avoid privilege escalation Link to this post

    Hey guys,

    Is this a bug or am I just being noob?

    In 2.4.7 when logging in as the default admin I am unable to assign users to the Administrators group. I checked the changelog and in 2.4.6 found the follow commit: https://github.com/silverstripe/sapphire/commit/de1f070

    By commenting out this function I was able to assign the accounts I had created to the administrator group using the default admin account.

    Is the default admin user not being properly assigned to the admin group? Thus the function is denying onChangeGroups()? Or am I just being noob?

    Robbie

  • borriej
    Avatar
    Community Member
    267 Posts

    Re: [BUG?] 2.4.6 - Avoid privilege escalation Link to this post

    im having the same problem! needed to go into phpMyAdmin to set a secondary admin manually! Please fix..

    365 Views
Page: 1
Go to Top

Want to know more about the company that brought you SilverStripe? Then check out SilverStripe.com

Comments on this website? Please give feedback.