-
Type:
Bug
-
Resolution: Fixed
-
Priority:
Low
-
Affects Version/s: 3.9.1
-
Component/s: Issue - Comments
-
3.09
The validateCommentUpdate(), hasPermissionToUpdate() and hasPermissionToDelete() methods on DefaultCommentService check the user's comment-related permissions but neglect to check whether they have a role/group security level viewable by the user attempting to delete a comment.