Filemin access for resellers

Hello,

I realized that the reseller have access to the whole system via the filemin module.. where could i restrict this.

Regards,

Status: 
Closed (works as designed)

Comments

Hmm, is your reseller able to see the home directory and files of users he isn't the reseller for?

yes, he is able to even modify them.... i think its like a root access he has..

It sounds like the behavior of the file manager with virtual users (such as resellers) needs to be reviewed.

But you can disable access to those users by going into Webmin -> Webmin -> Webmin Users -> USERNAME -> Available Webmin Modules, and there you can disable access to Filemin.

yea please, this can be considered as a security flaw.. should i raise the important of this ticket?

Priority: Normal » Major

Virtualmin resellers don't get granted access to the Filemin module by default though, so it's not surprising that if one was manually granted access they would have the default (unlimited) permissions.

Thanks Jamie for the clarification.. should we close this ticket?

Status: Active » Closed (works as designed)