Uploaded image for project: 'Project Simple'
  1. Project Simple
  2. ST-250

Insecure direct Object Reference: Confirmation statement

    Details

    • Type: Bug
    • Status: Closed
    • Priority: Medium
    • Resolution: Done
    • Component/s: BenAdmin
    • Labels:
      None
    • Module:
      BenAdmin - Security
    • Reported by:
      Support
    • Item State:
      Production Complete - Closed
    • Issue Importance:
      Must Have

      Description

      URL:
      https://wt-stage.harbinger.in/Assets/Temp/d4b28f08-dfb5-4923-850c-c53bac2383f6.pdf

      Description:
      login with employee credentials and in confirmation statement there is
      Option to export pdf. This link can be directly accessed and viewed from different machines without Credentials.

      Resolution:
      Restrict all post login pages from getting accessed directly.
      Authorization of the user specific resource must be implemented and publicly they should not be accessible

        Attachments

          Activity

          Transition Time In Source Status Execution Times
          Vijayendra Shinde (Inactive) made transition -
          Open In Development
          17s 1
          Sachin Hingole (Inactive) made transition -
          In LB Testing Reopen in Local
          1h 25m 2
          Sachin Hingole (Inactive) made transition -
          Reopen in Local In Development
          1h 30m 2
          Sachin Hingole (Inactive) made transition -
          In Development In LB Testing
          6d 1h 51m 3
          Deepali Tidke (Inactive) made transition -
          In LB Testing Stage Testing
          5d 20h 54m 1
          Deepali Tidke (Inactive) made transition -
          Stage Testing In Production Testing
          2s 1
          Rakesh Roy (Inactive) made transition -
          In Production Testing Production Complete
          7d 9h 20m 1
          Rakesh Roy (Inactive) made transition -
          Production Complete Closed
          14s 1

            People

            Assignee:
            sachin.hingole Sachin Hingole (Inactive)
            Reporter:
            vijayendra Vijayendra Shinde (Inactive)
            Developer:
            Kumar Chhajed (Inactive)
            Votes:
            0 Vote for this issue
            Watchers:
            5 Start watching this issue

              Dates

              Created:
              Updated:
              Resolved:
              Pre-Prod Due Date:
              Production Due Date: