MantisBT: master-2.28 69e0180f

Author Committer Branch Timestamp Parent
dregad dregad master-2.28 2026-03-27 13:53 master-2.28 3f952e68
Affected Issues  0036995: CVE-2026-34390: Privilege Escalation from Manager to Administrator role per project basis
Changeset

Fix privilege escalation in ProjectUsersAddCommand

Prevents MANAGER users from upgrading themselves or other users to
project-level ADMINISTRATOR.

Fixes 0036995

mod - core/commands/ProjectUsersAddCommand.php Diff File