Administrator users can add a usergroups to users for which they don't have the authorization level themselves

Administrator users can add a usergroups to users for which they don't have the authorization level themselves

Summary

An administrator user can add a user group to a user, of which it is not a member of itself.

Description

An administrator user can add a user group to a user, of which it is not a member of itself.

Solution

An administrator can only add those authorization levels to a group, which it has itself. An administator user can only remove authorization levels from a group which it has itself. An administrator user can only delete user groups for which it has all configured authorization levels. It is not possible to rename a user group.

Issue Number: 28506
Fixed on Date: 5.2.2013
Versions: 7.00 0 BUILD 7