Submitted by adamjedgar on Thu, 02/21/2019 - 18:23 Pro Licensee
logged into a virtual server as its administrator.
ran the phpmyadmin installer script
when i log into phpmyadmin as the virtual server admin user, i have full access to every database on all virtual servers on the system.
The virtual server admin user is not a member of any groups.
i do not understand how this should even be possible!
Status:
Needs work
Comments
Submitted by adamjedgar on Thu, 02/21/2019 - 18:36 Pro Licensee Comment #1
Submitted by JamieCameron on Fri, 02/22/2019 - 00:14 Comment #2
That does seem wrong - can you actually access those databases, or just see their names?
Submitted by ADDISON74 on Mon, 02/25/2019 - 12:11 Comment #3
When you install phpMyAdmin you can choose what databases to see in its interface. As is constructed Virtualmin, you can access only the databases with based on your privileges. I have seriously doubts with admin account from VM1 you can databases from VM1.
In the past I risen up an issue related to phpMyAdmin. You can use phpMyAdmin installation from VM1 to manage databases from VM2, but only with admin account from VM2. I wanted to find a way to limit phpMyAdmin, RoundCube installation being use only in its root folder and only by that admin account.