17
Views
1
Comments
[Multitenant Management] blocked_ips page roles
Question
multitenant-management
Web icon
Forge component by Carlos Alfaro

Hi,

We noticed that all but 1 screen have only usermanager role active. The blocked_ips page is available to registered users. Has this been done on purpose? If not, can you correct this for the new version?

cheers


Came here to report the same issue. This is a security vulnerability because it allows unprivileged users to perform a privileged operation, potentially negating the platform's brute force countermeasures. I'm going to fix this issue in my factory, but the main branch should be updated.

Community GuidelinesBe kind and respectful, give credit to the original source of content, and search for duplicates before posting.