T85589

BIG RISK Issue: Option to assign external clients to internal confidential things
Fitsuite
https://hub.app.geeks.ltd/accounting/SLT/Overdue-Balance/Add-action.aspx?.Client=97d9a129-aa9f-470f-a291-4a69e56ac6f7&ReturnUrl=%2fSLT%2fOverdue-Balance.aspx
Searching for myself to assign or cc people
Started typing my name, selection of clients appeared in the drop down

Just adding here that it would be easy to say well just don't select them but it's high risk of accidentally selecting and sharing very sensitive info about other clients overdue balances to other clients.
Only geeks should be selectable
Could have selected any client, would not have wanted to find out what happens if I actually had selected them as likely outcome would be they receive an email about another client's overdue balance.