Administrator users can add a usergroups to users for which they don't have the authorization level themselves
Summary
An administrator user can add a user group to a user, of which it is not a member of itself.
Description
An administrator user can add a user group to a user, of which it is not a member of itself.
Solution
An administrator can only add those authorization levels to a group, which it has itself. An administator user can only remove authorization levels from a group which it has itself. An administrator user can only delete user groups for which it has all configured authorization levels. It is not possible to rename a user group.
Issue Number: 28506
Fixed on Date: 5.2.2013
Versions: 7.00 0 BUILD 7