| PP 5.62: Guest can delete images without this userright in admin panel!
PP 5.62: Guest can delete images without this userright in admin panel!
Hi,
we have a usergroup called "test account". This usergroup is allowed to upload images, but not to delete. Maximum disk space 1MB.
Now they found a trick how to delete their photos although in the user control panel this group is not allowed to delete at all.
I need a fix for this asap, since this trick is spreading like fire since Monday on my board.
The way how they do this trick:
1. They go in their own user profile and click on "statistics".
2. They click on "manage photos" and select the specific category in which they want to delete the image
3. They check "delete" on teh right side, click on the button and the image is deleted although this user does not have the right to do it.
I can uplaod screenshots later on too
How can I fix this asap?
|