General Users can change their own profile to Admin.

I love this CRM app, but I found a potentially dangerous flaw in the script. I don’t know anything about ASP scripts, but when I create a user with General priveledges, that user can change his own profile status to Admin if he chooses, granting that user access to the entire database and no longer only his own data. Is there a fix for this?

Speak Your Mind