I have found a huge security lag in the 5.5 (and previews version).
Place of lag: Module EMails
Description:
When you compose an EMail and you click the "To" "Cc" or "BCC" button you can seach for ALL E-Mail adresses even if the role managment restricts to see only the OWNER contacts/EMail adresses. It means the E-Mail Seach function totally ignores the Role-Management !!
This is a huge lag of securutie because you can bypass the role managment by the EMail seach function. Our external empleyees are able withthis to export all our Email adresses even we have forbidden this. This must be fixed!
Regard
Max Seegräber
Seegräber


LinkBack URL
About LinkBacks




Reply With Quote

Bookmarks