Uploaded image for project: 'Project Simple'
  1. Project Simple
  2. ST-250

Insecure direct Object Reference: Confirmation statement

    Details

    • Type: Bug
    • Status: Closed
    • Priority: Medium
    • Resolution: Done
    • Component/s: BenAdmin
    • Labels:
      None
    • Module:
      BenAdmin - Security
    • Reported by:
      Support
    • Item State:
      Production Complete - Closed
    • Issue Importance:
      Must Have

      Description

      URL:
      https://wt-stage.harbinger.in/Assets/Temp/d4b28f08-dfb5-4923-850c-c53bac2383f6.pdf

      Description:
      login with employee credentials and in confirmation statement there is
      Option to export pdf. This link can be directly accessed and viewed from different machines without Credentials.

      Resolution:
      Restrict all post login pages from getting accessed directly.
      Authorization of the user specific resource must be implemented and publicly they should not be accessible

        Attachments

          Activity

          No work has yet been logged on this issue.

            People

            Assignee:
            sachin.hingole Sachin Hingole (Inactive)
            Reporter:
            vijayendra Vijayendra Shinde (Inactive)
            Developer:
            Kumar Chhajed (Inactive)
            Votes:
            0 Vote for this issue
            Watchers:
            5 Start watching this issue

              Dates

              Created:
              Updated:
              Resolved:
              Pre-Prod Due Date:
              Production Due Date: