Uploaded image for project: 'Project Simple'
  1. Project Simple
  2. ST-91

Old password not required to change email. Old password should be mandatory.

    Details

    • Type: Enhancement
    • Status: Closed
    • Priority: Medium
    • Resolution: Done
    • Component/s: BenAdmin
    • Labels:
    • Module:
      BenAdmin - Security
    • Reported by:
      Support
    • Item State:
      Production Complete - Closed

      Description

      Praetorian discovered this vulnerability while examining the application’s user account management features. This feature does not require a user's current password to update their email address. This is shown in the figure below.

      Ideally on Partner/Broker or company admin page, we should not able to update any field without asking old password. This password should not be sent to client side for verification.

        Attachments

          Issue Links

            Activity

            Hide
            niteen.surwase Niteen Surwase (Inactive) added a comment -

            *Page : *
            Partner/Broker Users and Admin Users (Try with all level user login)

            Description :
            When Partner/Broker/Company Admin make changes in self or another Partner/Broker/Company Admin then pop-up displays. This pop-up asks for logged-in password. When user enters correct password then its make changes in user, otherwise, it shows wrong password message. For Super Admin login it is not showing Old password popup. It directly updates data.
            Try with all user logins for Partner/Broker/Company Admin screens

            For users scenario follow the attached excel-sheet!

            Show
            niteen.surwase Niteen Surwase (Inactive) added a comment - *Page : * Partner/Broker Users and Admin Users (Try with all level user login) Description : When Partner/Broker/Company Admin make changes in self or another Partner/Broker/Company Admin then pop-up displays. This pop-up asks for logged-in password. When user enters correct password then its make changes in user, otherwise, it shows wrong password message. For Super Admin login it is not showing Old password popup. It directly updates data. Try with all user logins for Partner/Broker/Company Admin screens For users scenario follow the attached excel-sheet!
            Hide
            niteen.surwase Niteen Surwase (Inactive) added a comment -

            Also check for Localization by login in 3 different languages

            Show
            niteen.surwase Niteen Surwase (Inactive) added a comment - Also check for Localization by login in 3 different languages
            Hide
            amitg Amit Gude (Inactive) added a comment -

            Assigning to Zeeshan

            Show
            amitg Amit Gude (Inactive) added a comment - Assigning to Zeeshan
            Hide
            Zeeshan.Chishty Zeeshan Chishty (Inactive) added a comment -

            Verified as Old Password is required to change mail id

            Show
            Zeeshan.Chishty Zeeshan Chishty (Inactive) added a comment - Verified as Old Password is required to change mail id
            Hide
            Zeeshan.Chishty Zeeshan Chishty (Inactive) added a comment -

            Verified on stage as Password is required to change mail id

            Show
            Zeeshan.Chishty Zeeshan Chishty (Inactive) added a comment - Verified on stage as Password is required to change mail id
            Hide
            rakeshr Rakesh Roy (Inactive) added a comment -

            Please let us know for any functionality testing is needed other that Security testing on this.

            Show
            rakeshr Rakesh Roy (Inactive) added a comment - Please let us know for any functionality testing is needed other that Security testing on this.
            Hide
            rakeshr Rakesh Roy (Inactive) added a comment -

            Zeeshan Chishty Once you verify this from security perspective, assign to Deepali Tidke for functional verification.

            Show
            rakeshr Rakesh Roy (Inactive) added a comment - Zeeshan Chishty Once you verify this from security perspective, assign to Deepali Tidke for functional verification.
            Hide
            Zeeshan.Chishty Zeeshan Chishty (Inactive) added a comment -

            Rakesh Roy we do not have production login and Production security testing is not recommended

            Show
            Zeeshan.Chishty Zeeshan Chishty (Inactive) added a comment - Rakesh Roy we do not have production login and Production security testing is not recommended
            Hide
            Zeeshan.Chishty Zeeshan Chishty (Inactive) added a comment -

            Old Password required for changing email confirmed on Production Server.

            Show
            Zeeshan.Chishty Zeeshan Chishty (Inactive) added a comment - Old Password required for changing email confirmed on Production Server.
            Hide
            kunal.kedari Kunal Kedari (Inactive) added a comment -

            Functional testing is done for this feature on Production now old password is required while changing email, this change is working as expected for different locale as well. As per comments Zeeshan Chishty verified it from security perspective, hence closing the ticket.

            Show
            kunal.kedari Kunal Kedari (Inactive) added a comment - Functional testing is done for this feature on Production now old password is required while changing email, this change is working as expected for different locale as well. As per comments Zeeshan Chishty verified it from security perspective, hence closing the ticket.

              People

              Assignee:
              kunal.kedari Kunal Kedari (Inactive)
              Reporter:
              vijayendra Vijayendra Shinde (Inactive)
              Developer:
              Niteen Surwase (Inactive)
              Votes:
              0 Vote for this issue
              Watchers:
              6 Start watching this issue

                Dates

                Created:
                Updated:
                Resolved: