This object is in archive! 

Security problem: User type "Tenant" can change/edit devices!

Robert Hercz shared this problem 7 years ago
Solved

Having installed Zipabox'es in 4 different locations, I started adding users (employees, family members) to the Zipabox setup in order to allow them to control stuff via the app, I just discovered that while member type "Tenant" cannot change devices via the iOS app, the user CAN CHANGE devices using the Android app and the my.zipato.com website.


For security reasons, I really cannot allow others access to our Zipato installations until this is fixed.


Any idea when this can be fixed?

Replies (2)

photo
1

Dear Robert,


Please, open a ticket on our support site: support.zipato.com so we could examine this directly on your box. We didn't got any other complaints about this so it could be possible that this is an isolated case in your system.


Best regards,

Pero Zovkic

photo
1

Pero,

I sumbitted a ticket.

Please send me an email with an email account I can add as a Tenant User so you can see this for yourself.

Brgds

Robert

Leave a Comment
 
Attach a file