TITLE:
Plesk file manager can delete Files with root rights!
PRODUCT, VERSION, OPERATING SYSTEM, ARCHITECTURE:Plesk Onyx, Version 17.5.3 Update #30, Ubuntu 16.04.2 LTS, x64
PROBLEM DESCRIPTION:The internal filemanager may seem to delete files created with the root owner. Theoretically, the user could delete all folders and all files with Plesk File Manager. Even if the file may only be read by root:
This fil can delete over the filemanager.
STEPS TO REPRODUCE:This fil can delete over the filemanager.
Create a file over SSH under root and change the file rights to: 0400
This file can delete with the filemanager under plesk panel.
ACTUAL RESULT:This file can delete with the filemanager under plesk panel.
All files and folders can be deleted
EXPECTED RESULT:It may be deleted only the files and folders that can describe the current user too.
ANY ADDITIONAL INFORMATION:
YOUR EXPECTATIONS FROM PLESK SERVICE TEAM:Confirm bug