Security problem in CE 10
Have you noticed this or have we setup the system wrong?
I signed in to Crystal Enterprise 10 and schedule a report, in the scheduling I selected the destination to be Email (SMTP). I checked the “Set the values to be used at schedule time here:” button and add Mary’s email address to the From: box (Mary.Jones@Company.com). I then added Joan’s and Bob’s addresses in the To: box (Joan.Smith@Company.com; Robert.Brown@Company.com) and my address to the CC: box (kmsalt@Company.com) to see the message. Check to not send the report. Schedule the report, when completed, the email I got, looks as if Mary sent it.
I have not been able to gray out the from box, in your old system INFO Desktop 7.5 there was not a from box, the system mail account was used.
Can we gray out the From box in the scheduler?
An evil-minded person could have fun with this new feature/bug by sending people emails using other email accounts.
At first, I was using my account, which was an admin account. Then I tested with a test account that had scheduling and view on demand rights, and it worked.
Have you noticed this or have we setup the system wrong?
I signed in to Crystal Enterprise 10 and schedule a report, in the scheduling I selected the destination to be Email (SMTP). I checked the “Set the values to be used at schedule time here:” button and add Mary’s email address to the From: box (Mary.Jones@Company.com). I then added Joan’s and Bob’s addresses in the To: box (Joan.Smith@Company.com; Robert.Brown@Company.com) and my address to the CC: box (kmsalt@Company.com) to see the message. Check to not send the report. Schedule the report, when completed, the email I got, looks as if Mary sent it.
I have not been able to gray out the from box, in your old system INFO Desktop 7.5 there was not a from box, the system mail account was used.
Can we gray out the From box in the scheduler?
An evil-minded person could have fun with this new feature/bug by sending people emails using other email accounts.
At first, I was using my account, which was an admin account. Then I tested with a test account that had scheduling and view on demand rights, and it worked.