welch Posted March 7, 2007 Share Posted March 7, 2007 I wouldn't say this is an big error, but I feel that it could be corrected for security and presentation. When an admin is logged in and opens another tab and goes to the client area, he can just enter a clients email and click login without a password and be taken to the account. Anything works just as long as the email is one of a client. 0 Quote Link to comment Share on other sites More sharing options...
Adam Posted March 7, 2007 Share Posted March 7, 2007 I wouldn't say this is an big error, but I feel that it could be corrected for security and presentation. When an admin is logged in and opens another tab and goes to the client area, he can just enter a clients email and click login without a password and be taken to the account. Anything works just as long as the email is one of a client. Hey, But he is an Admin! He should have access to that stuff From, Adam 0 Quote Link to comment Share on other sites More sharing options...
welch Posted March 7, 2007 Author Share Posted March 7, 2007 I just found it wierd that it works like that. Not so much an issue, but I thought I would point it out. 0 Quote Link to comment Share on other sites More sharing options...
Steve Posted March 7, 2007 Share Posted March 7, 2007 That's meant to happen, it's one of the new features in V3. 0 Quote Link to comment Share on other sites More sharing options...
welch Posted March 7, 2007 Author Share Posted March 7, 2007 That's meant to happen, it's one of the new features in V3. The feature was added in the Administrator panel under the optional link "Login as user", not the abondonment of password verification. I know logging in as a client is a feature of v3. Again, found it a bit odd of how the system was setup to login as user. 0 Quote Link to comment Share on other sites More sharing options...
WHMCS CEO Matt Posted March 7, 2007 WHMCS CEO Share Posted March 7, 2007 This is not a security issue. If you are logged in as an admin it is designed to work in this way. It doesn't let just anyone login however - they must be logged in as admins to have access to any account. 0 Quote Link to comment Share on other sites More sharing options...
Recommended Posts
Join the conversation
You can post now and register later. If you have an account, sign in now to post with your account.