Every user can modify open_basedir protection, even if they have no permissions whatsoever. This panel cannot be considered secure anymore, there should be an option for open_basedir across all sites and don’t let users change it. I just got a new customer and if he wanted to he could steal all websites data.
un
under
#1