- Affected version
- 2.1.6a
While administrators are prevented from removing the only/their own administrator record, nothing prevents them from deleting their own account entirely. This can lead to a situation where there are no administrators at all, which I believe can only be rectified through direct database queries since the
Administrators should probably be restricted from removing their own accounts.
superAdmins
configuration option was removed from XF2.Administrators should probably be restricted from removing their own accounts.