Uploaded image for project: 'Project Simple'
  1. Project Simple
  2. ST-232

Information Disclosure for File Upload URL

    Details

    • Type: Enhancement
    • Status: Closed
    • Priority: Medium
    • Resolution: Done
    • Component/s: BenAdmin
    • Labels:
      None
    • Module:
      BenAdmin - Security
    • Reported by:
      Support
    • Item State:
      Production Complete - Closed
    • Issue Importance:
      Must Have

      Description

      URL: https://10.0.2.56/Platform/common/UploadFilePost

      Default Error page is displayed if we forcefully browse the URL without login.
      Default error should not be displayed.

        Attachments

          Issue Links

            Activity

            Hide
            vijayendra Vijayendra Shinde (Inactive) added a comment -

            We have shown Page not found message instead of Default error mesage.

            Show
            vijayendra Vijayendra Shinde (Inactive) added a comment - We have shown Page not found message instead of Default error mesage.
            Hide
            Zeeshan.Chishty Zeeshan Chishty (Inactive) added a comment -

            Confirmed that Page Not Found is displayed now and no Information is disclosed.

            Show
            Zeeshan.Chishty Zeeshan Chishty (Inactive) added a comment - Confirmed that Page Not Found is displayed now and no Information is disclosed.
            Hide
            Zeeshan.Chishty Zeeshan Chishty (Inactive) added a comment - - edited

            Vijayendra ShindeOn Stage below error is displayed and not Page not Found.
            Server Error in '/Platform' Application.

            Runtime Error

            Description: An exception occurred while processing your request. Additionally, another exception occurred while executing the custom error page for the first exception. The request has been terminated.

            Show
            Zeeshan.Chishty Zeeshan Chishty (Inactive) added a comment - - edited Vijayendra Shinde On Stage below error is displayed and not Page not Found. Server Error in '/Platform' Application. Runtime Error Description: An exception occurred while processing your request. Additionally, another exception occurred while executing the custom error page for the first exception. The request has been terminated.
            Hide
            Zeeshan.Chishty Zeeshan Chishty (Inactive) added a comment -

            Confirmed that we are getting Page Not Found on stage .

            Show
            Zeeshan.Chishty Zeeshan Chishty (Inactive) added a comment - Confirmed that we are getting Page Not Found on stage .
            Hide
            deepalit Deepali Tidke (Inactive) added a comment -

            checked on production with following link: https://www.workterra.net/WORKTERRA/common/UploadFilePost

            Page not found is coming

            Show
            deepalit Deepali Tidke (Inactive) added a comment - checked on production with following link: https://www.workterra.net/WORKTERRA/common/UploadFilePost Page not found is coming

              People

              Assignee:
              deepalit Deepali Tidke (Inactive)
              Reporter:
              vijayendra Vijayendra Shinde (Inactive)
              Developer:
              Vijayendra Shinde (Inactive)
              Votes:
              0 Vote for this issue
              Watchers:
              3 Start watching this issue

                Dates

                Created:
                Updated:
                Resolved:
                Pre-Prod Due Date:
                Production Due Date: