Fixed Any admin can export user data

Kirby

Well-known member
Affected version
2.0.6a
Steps to reproduce
  1. Create a new admin but do not assign any admin permissions
  2. Log into backend with the newly created admin
Expected Result
The account does not see any navigational links except Tools.
When accessing data-portability/export, an error is being shown that the user does not have enough permissions

Actual Result
The account does not see any navigational links except Tools.
When accessing data-portability/export via direct URL, the data export form is being shown and I can successfully export any user.

This seems a serious issue to me as it basically allows any admin to get access to sensitive user data.
 
Back
Top Bottom