"It depends"
What level of access did the admin have? Could they upload files to the server? Whats the server config? Were there any exploitable services or modules running?
If you've got to ask the question why continue to allow them admin level ?
He/she needs to get skin in the game and buy their own xf license and host it up cheap themselves. Just my 2 cents.They don't have any admin/moderator privileges yet. But they wish to have permission to work on a separate isolated installation of XenForo for testing purposes. Furthermore, we do NOT have the budget (or literally any budget at all) to hire a sec. consultant. And that's OK. I don't expect anyone to harden my server for free at all. But I do need to know...
Is there a high risk?
He/she needs to get skin in the game and buy their own xf license and host it up cheap themselves. Just my 2 cents.
Just have a separate vps server for test install - cheap hourly billed VPSes can be had at linode and digitalocean and upcloud cloud vps providers for just these kind of tasks.They don't have any admin/moderator privileges yet. But they wish to have permission to work on a separate isolated installation of XenForo for testing purposes
We use essential cookies to make this site work, and optional cookies to enhance your experience.