Results 1 to 4 of 4
Like Tree1Likes
  • 1 Post By dbjohnso86

Thread: Personal Email Security Question

  1. #1
    dbjohnso86 is offline Junior Member
    Join Date
    Jan 2012
    Posts
    4

    Default Personal Email Security Question

    Is it normal that a user can see other users "Personal Mail Configurations" and either edit them and or delete them. It appears that all users can see all other users Email configs and delete them even though these users are not admins.
    Last edited by dbjohnso86; 2012-01-25 at 01:19 PM.

  2. #2
    Chris_C's Avatar
    Chris_C is offline Sugar Community Member
    Join Date
    Jun 2011
    Location
    Connecticut
    Posts
    227

    Default Re: Personal Email Security Question

    You're right - When you go into Emails / Settings / Mail Accounts, and hover over the "Type (i)" info icon, the popup info box says "Personal: Email account accessible by you. Only you can manage and import emails from this account."

    So it SHOULD be visible/editable only by the individual user and the admin.

    On your Sugar instance - does it list other users' Personal Email Accounts there, and lets you edit the settings ?

    What version are you running?
    On what hosting platform - on-premise or hosted ?
    Hosted where?

  3. #3
    dbjohnso86 is offline Junior Member
    Join Date
    Jan 2012
    Posts
    4

    Default Re: Personal Email Security Question

    The working platform is Windows 2008 R2 running SCE 6.2.3 (Build 6658)
    however after seeing this I built a Linux(Centos 6) back end with SCE 6.2.3 and noticed the same ?issue?
    So I then re-built a 2nd Linux box and went with 6.3.1 this time and had the same issue...


    If I go Emails / Settings / Mail Accounts only the account you would expect to see is shown however if for example another persons Email folder is visible in the "Last Viewed" section at which point if I click on their folder I can then "Edit" it or "Delete" their email confi.

    Also if I get to an action where the "All Mail Accounts" icon is visible
    I can then show a listing of ALL personal emails (in the list that then appears they all show as "personal" as the type and not Group.... At that point I can then select any or all of them and delete them all... This is true for all accounts...

    This is with installing sugar from scratch and populating with demo data OR with using a clean install with no demo data or accounts and just creating (2) or more employee accounts from scratch...




    Quote Originally Posted by Chris_C View Post
    You're right - When you go into Emails / Settings / Mail Accounts, and hover over the "Type (i)" info icon, the popup info box says "Personal: Email account accessible by you. Only you can manage and import emails from this account."

    So it SHOULD be visible/editable only by the individual user and the admin.

    On your Sugar instance - does it list other users' Personal Email Accounts there, and lets you edit the settings ?

    What version are you running?
    On what hosting platform - on-premise or hosted ?
    Hosted where?
    Chris_C likes this.

  4. #4
    Chris_C's Avatar
    Chris_C is offline Sugar Community Member
    Join Date
    Jun 2011
    Location
    Connecticut
    Posts
    227

    Default Re: Personal Email Security Question

    dbjohnso86,

    You definitely found a bug. Good job.

    You should copy paste all the detail above, into the Sugar bug system, so the devs can fix it:

    SugarCRM Bug Tracker | Open Source Business & Social CRM - SugarCRM

Thread Information

Users Browsing this Thread

There are currently 1 users browsing this thread. (0 members and 1 guests)

Similar Threads

  1. Sugar CE Personal IMAP Mail Question
    By dbjohnso86 in forum General Discussion
    Replies: 3
    Last Post: 2012-01-27, 07:47 PM
  2. Personal Email Settings Tab not functioning
    By FancyFace in forum Help
    Replies: 3
    Last Post: 2009-11-14, 01:11 PM
  3. Personal Email
    By RickBojahra in forum Help
    Replies: 1
    Last Post: 2006-08-18, 07:56 PM
  4. Sugar 4 Personal Email Inbox
    By kickedmydog in forum Feature Requests
    Replies: 3
    Last Post: 2005-12-23, 02:51 PM

Tags for this Thread

Bookmarks

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •