Major Security Flaw

Some of you may already have found this but I'll post it anyway.

While looking thru a items movement report, and I found that double clicking the user that had sold a item , RMS bypassed all security and let a user with reports access , full control of administrator cashiers accounts . Could change admins passwords, security settings, security levels etc.

Dennis

Reply to
MHPNW STAFF
Loading thread data ...

Rob, we are running v.1.2.0185, I haven't installed v.1.3 as yet

I did find that this process only works with other cashiers with admin privileges. We have level 0,1 levels of admins, and certain grayed out sections for each . But this glitch allows any level of admin's to access higher level of acct's. properties.

Thanks Dennis

Reply to
MHPNW STAFF

If these people don't need to modify any of the cashier properties then I would deselect Administrator Rights. But I would still open a ticket with MS Tech Support to let them know.

Rob

Reply to
Rob

BeanSmart website is not affiliated with any of the manufacturers or service providers discussed here. All logos and trade names are the property of their respective owners.