-
Type:
Bug
-
Resolution: Fixed
-
Priority:
High
-
Affects Version/s: 2.10.3
-
Component/s: None
- Add a page
- Set viewing restrictions to user1 only
- Add an attachment - 'Sample.doc'
- Log in as user2 - confirm that you cannot see the restricted page
- Add a page, and use the viewfile macro
- Enter the location of the attachment on the restricted page
The contents of the attachment can now be viewed by user2. This is a serious violation of page permissions.