Description
While we currently do prevent users from adding a role to their ApplicationUser, we do not have a restriction to prevent a user from adding a user from an ApplicatoinRole. So if they were to guess what a role is, this might be a backdoor.