<?xml version="1.0"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
		<id>https://wiki.owasp.org/index.php?action=history&amp;feed=atom&amp;title=Multiple_admin_levels</id>
		<title>Multiple admin levels - Revision history</title>
		<link rel="self" type="application/atom+xml" href="https://wiki.owasp.org/index.php?action=history&amp;feed=atom&amp;title=Multiple_admin_levels"/>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Multiple_admin_levels&amp;action=history"/>
		<updated>2026-04-11T10:02:09Z</updated>
		<subtitle>Revision history for this page on the wiki</subtitle>
		<generator>MediaWiki 1.27.2</generator>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Multiple_admin_levels&amp;diff=79008&amp;oldid=prev</id>
		<title>Allison Nixon: Created page with ' {{Template:Vulnerability}} Last revision (02/27/10): '''{{FEB}}/{{27}}/{{2010}}'''  Vulnerabilities Table of Contents  ==Description==  In an applic…'</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Multiple_admin_levels&amp;diff=79008&amp;oldid=prev"/>
				<updated>2010-02-27T20:20:11Z</updated>
		
		<summary type="html">&lt;p&gt;Created page with &amp;#039; {{Template:Vulnerability}} Last revision (02/27/10): &amp;#039;&amp;#039;&amp;#039;{{FEB}}/{{27}}/{{2010}}&amp;#039;&amp;#039;&amp;#039;  &lt;a href=&quot;/index.php?title=ASDR_TOC_Vulnerabilities&amp;amp;action=edit&amp;amp;redlink=1&quot; class=&quot;new&quot; title=&quot;ASDR TOC Vulnerabilities (page does not exist)&quot;&gt;Vulnerabilities Table of Contents&lt;/a&gt;  ==Description==  In an applic…&amp;#039;&lt;/p&gt;
&lt;p&gt;&lt;b&gt;New page&lt;/b&gt;&lt;/p&gt;&lt;div&gt;&lt;br /&gt;
{{Template:Vulnerability}}&lt;br /&gt;
Last revision (02/27/10): '''{{FEB}}/{{27}}/{{2010}}'''&lt;br /&gt;
&lt;br /&gt;
[[ASDR_TOC_Vulnerabilities|Vulnerabilities Table of Contents]]&lt;br /&gt;
&lt;br /&gt;
==Description==&lt;br /&gt;
&lt;br /&gt;
In an application with administrators that have the ability to alter login credentials of users, if there are multiple levels of administrator permissions, there needs to be a control preventing administrators with lower permission levels from altering login credentials of higher level admins.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==Risk Factors==&lt;br /&gt;
&lt;br /&gt;
* Likelihood of this happening relies on an attacker getting control of a lower level admin account in the first place.  &lt;br /&gt;
* Administrator misconduct or mistakes could be made worse if they could easily escalate their own permissions.&lt;br /&gt;
* There is no point to create administrators with different levels of permissions if you don't prevent them from easily escalating their own permissions.&lt;/div&gt;</summary>
		<author><name>Allison Nixon</name></author>	</entry>

	</feed>