No Code Attached Yet
avatar coolcat-creations
coolcat-creations
10 Feb 2022

Steps to reproduce the issue

With this setting all Users who are registered, and have the "Receive System Mails" Flag on "Yes" (1) will receive an email notification that a new User registered on the Website

The Email which is sent out contains even the Greeting "Hello Administrator"

grafik

Expected result

When I set "Send Mail to Administrators" to yes, I expect that only users with Administration (ACL) rights will receive a mail.

Actual result

All users who are flagged to receive system emails receive an email, greeting them as Administrator and informed about sensitive data (User Email Address and Name)

System information (as much as possible)

Joomla 3.10.5

Additional comments

  1. Either the field Send Mail to Administrators has to be renamed to Send System Messages to all enabled users (or similar) or
  2. There needs to be an additional check to only send out this information only to the Administrator level.
avatar coolcat-creations coolcat-creations - open - 10 Feb 2022
avatar joomla-cms-bot joomla-cms-bot - change - 10 Feb 2022
Labels Added: No Code Attached Yet
avatar joomla-cms-bot joomla-cms-bot - labeled - 10 Feb 2022
avatar coolcat-creations coolcat-creations - change - 10 Feb 2022
The description was changed
avatar coolcat-creations coolcat-creations - edited - 10 Feb 2022
avatar coolcat-creations coolcat-creations - change - 10 Feb 2022
The description was changed
avatar coolcat-creations coolcat-creations - edited - 10 Feb 2022
avatar blueforce
blueforce - comment - 10 Feb 2022

This is also the case in version 4.x
Bildschirmfoto 2022-02-10 um 11 32 45

avatar brianteeman
brianteeman - comment - 10 Feb 2022
  1. Either the field Send Mail to Administrators has to be renamed to Send System Messages to all enabled users (or similar) or
  2. There needs to be an additional check to only send out this information only to the Administrator level.

For me option 1 is just covering up the problem.

As these emails always/often include links that require access to the admin interface then they should not be sent to a user who does not have the required acl access irrespective of the setting for this checkbox.

avatar Quy Quy - change - 10 Feb 2022
Status New Closed
Closed_Date 0000-00-00 00:00:00 2022-02-10 17:17:42
Closed_By Quy
avatar Quy Quy - close - 10 Feb 2022
avatar Quy
Quy - comment - 10 Feb 2022

Closing per PR #36997.

Add a Comment

Login with GitHub to post a comment