-
Type: Bug
-
Status: Closed
-
Priority: High
-
Resolution: Bug Fixed
-
Affects Version/s: None
-
Fix Version/s: None
-
Component/s: UI Refresh
-
Labels:None
-
Environment:Others
-
Bug Type:Functional
-
Bug Severity:Medium
-
Level:Admin
-
Module:Platform
-
Reported by:Harbinger
-
Company:All Clients/Multiple Clients
-
Item State:LB QA - In Testing
-
Issue Importance:Q2
[Security]-[Authorization Failure] Employee can access all Admin pages over the URL and able to update the customization/settings for those pages.
Environment : Azure
Replication Steps:
1. Login as Company Admin
2. GO to Company Information Page.
3. Copy the URL
4. Login with Employee of same company in another browser.
5. Paste the URL in employee's session.
6. Access the Admin pages and try to update settings.
Observed Same behavior on multiple pages like All tabs in Company Information, Manage Admin Users, Security Page, Site Branding and Themes etc.
It seems that this issue is with all pages and necessary access level entries are missing.
Expected Result:
As soon as any admin level page URL is accessed by Employee Login it should show the Unauthorized Access page and restrict user for further actions.
CC : Rakesh RoySachin HingoleHrishikesh DeshpandeVijay SiddhaVijayendra ShindeRohan J KhandaveBharti SatputeSamir
- relates to
-
NF-2714 Vulnerability Assessment and Penetration Testing for Workterra on Azure US environment.
- To Do