Thursday, March 01, 2007

Unauthorized user able to create posting !!!!!!

This case was reported on microsoft.public.cmserver.general group

Case:
We have multiple websites hosted on the same CMS farm by mapping Channel Names to Host Header Names. On one of the sites any user whose is a member our AD group can create new page/posting even though they are not assigned any role in the CMS system. This happens only on one site among the several sites in the server.
Have anyone come across this issue before.

Answer:
please check your rights groups.
Sounds as if the guest account has been assigned to a non-Subscriber rights group.
This is not supported and will lead to such an issue.

Answered by: Stefan Goßner

No comments: