-
Notifications
You must be signed in to change notification settings - Fork 2
Open
Labels
Description
From @asuweb on February 14, 2017 8:53
The new domain administration features where domain admins can add users needs documenting prior to release.
It introduces a security issue when existing domain admins are in the format domain.tld. They can then see other domain admins user details, and can change other domain admins passwords. This is due to the change in methodology with the introduction of the new features.
The new features are very welcome, but it does alter the way some people might assign accounts and needs to be understood before upgrading.
Copied from original issue: mailwatch/MailWatch#525