Bug #2353
closedMeetings(Modify Right)->Problem on Viewing Meetings list by user provided the user is having only Meetings-Modifty access right
0%
1.Login as Meetings-Modify access right user
2.Expand activities tab
3.Click on meetings link
4.Check the results
Description
Meetings(Modify Right)->The system allowing to view all the meetings by user provided the user is having only Meetings-modify access right.
Impact 1->The modify user can assign their own KPI report for other department meetings. So there is no security here.
Impact 2->The modify user can delete other department meetings.
Expected Output-> If the user is having Meetings-Modify right, they can able to create new meetings and could add their own KPI/DASHBOARD for their own meetings also can delete their own meetings. Other department meetings should not list under any entity.Only module admin can see all the meetings in listing page under any one entity.