-
Type:
Bug
-
Status:
Closed
-
Priority:
Medium
-
Resolution:
Done
-
Affects Version/s:
None
-
Fix Version/s:
None
-
-
-
-
Module:
Platform
- Security
-
-
Item State:
Production Complete
-
Issue Importance:
Must Have
-
Sprint:
Bugs-Must Fix- Pilot July2016
1] Login to the application on local environment using following URL:
https://wt-stage.harbinger.in
2] From Home page search and select a company for which testing needs to be carried out using "Search Company" section.
3] Click on "Ben Admin" menu.
4] Click on "Customizer" icon from left navigation menu.
5] Click on "Rates" link which is submenu of "Customizer", user gets navigate to "Rates" details page.
6] Click on "Import" button displaying at top right hand side of the "Rates" page, the "Rate Import" window gets poped up, click on “Add New Rate” tab.
7] Browse the file new rate file.
8] Now browse a image or .exe/.dll file with whose extension is tampered. (i.e. extension changed to .xlsm/.xlsx)
9] Click on "Upload" button.
Actual Result:
Application is allowing to upload such files and when user click on “Import Rate” button the Server error is displaying.
Expected Result:
Not supported extensions files (.txt, .pdf, image files, executable files etc) should not be get uploaded after tampering the extension.
{"report":{"apdex":1,"isInitial":true,"journeyId":"582d93d3-6df7-42b3-9349-b1e82f26ad52","key":"jira.project.issue.view-issue","navigationType":0,"readyForUser":836.8000001907349,"redirectCount":0,"resourceLoadedEnd":972.8000001907349,"resourceLoadedStart":147.5,"resourceTiming":[{"duration":229.10000038146973,"initiatorType":"link","name":"https://jira.workterra.net/s/3003653444a1e1a85555cab7dcfb3a21-CDN/-w431t5/805012/9a9e1fae3639050b38ac467c3aa37e79/2e46d90b5cae895c9c38649c9d510130/_/download/contextbatch/css/_super/batch.css","startTime":147.5,"connectEnd":0,"connectStart":0,"domainLookupEnd":0,"domainLookupStart":0,"fetchStart":147.5,"redirectEnd":0,"redirectStart":0,"requestStart":0,"responseEnd":376.6000003814697,"responseStart":0,"secureConnectionStart":0},{"duration":229.30000019073486,"initiatorType":"link","name":"https://jira.workterra.net/s/dd6a0911920485696ac20493290df627-CDN/-w431t5/805012/9a9e1fae3639050b38ac467c3aa37e79/3abe50d469404b639745df44b51476b6/_/download/contextbatch/css/jira.browse.project,jira.view.issue,project.issue.navigator,jira.global,atl.general,-_super/batch.css?agile_global_admin_condition=true&jag=true&jira.create.linked.issue=true&richediton=true","startTime":147.69999980926514,"connectEnd":0,"connectStart":0,"domainLookupEnd":0,"domainLookupStart":0,"fetchStart":147.69999980926514,"redirectEnd":0,"redirectStart":0,"requestStart":0,"responseEnd":377,"responseStart":0,"secureConnectionStart":0},{"duration":229.19999980926514,"initiatorType":"link","name":"https://jira.workterra.net/s/d41d8cd98f00b204e9800998ecf8427e-CDN/-w431t5/805012/9a9e1fae3639050b38ac467c3aa37e79/8.5.0/_/download/batch/com.atlassian.auiplugin:split_aui.pattern.label/com.atlassian.auiplugin:split_aui.pattern.label.css","startTime":147.9000005722046,"connectEnd":0,"connectStart":0,"domainLookupEnd":0,"domainLookupStart":0,"fetchStart":147.9000005722046,"redirectEnd":0,"redirectStart":0,"requestStart":0,"responseEnd":377.1000003814697,"responseStart":0,"secureConnectionStart":0},{"duration":229,"initiatorType":"link","name":"https://jira.workterra.net/s/bd548f27bbf8f278bd83b60dd3284ed8-CDN/-w431t5/805012/9a9e1fae3639050b38ac467c3aa37e79/1.0/_/download/batch/jira.webresources:global-static-adgs/jira.webresources:global-static-adgs.css","startTime":148.10000038146973,"connectEnd":0,"connectStart":0,"domainLookupEnd":0,"domainLookupStart":0,"fetchStart":148.10000038146973,"redirectEnd":0,"redirectStart":0,"requestStart":0,"responseEnd":377.1000003814697,"responseStart":0,"secureConnectionStart":0},{"duration":228.89999961853027,"initiatorType":"link","name":"https://jira.workterra.net/s/70725731a158a7140f19ddbd4201ba27-CDN/-w431t5/805012/9a9e1fae3639050b38ac467c3aa37e79/1.0/_/download/batch/jira.webresources:global-static/jira.webresources:global-static.css","startTime":148.4000005722046,"connectEnd":0,"connectStart":0,"domainLookupEnd":0,"domainLookupStart":0,"fetchStart":148.4000005722046,"redirectEnd":0,"redirectStart":0,"requestStart":0,"responseEnd":377.30000019073486,"responseStart":0,"secureConnectionStart":0},{"duration":238.30000019073486,"initiatorType":"script","name":"https://jira.workterra.net/s/f2623af22c15df767ec6ff268ae0b8bd-CDN/-w431t5/805012/9a9e1fae3639050b38ac467c3aa37e79/2e46d90b5cae895c9c38649c9d510130/_/download/contextbatch/js/_super/batch.js?locale=en-US","startTime":148.5,"connectEnd":148.5,"connectStart":148.5,"domainLookupEnd":148.5,"domainLookupStart":148.5,"fetchStart":148.5,"redirectEnd":0,"redirectStart":0,"requestStart":148.5,"responseEnd":386.80000019073486,"responseStart":386.80000019073486,"secureConnectionStart":148.5},{"duration":259.69999980926514,"initiatorType":"script","name":"https://jira.workterra.net/s/6ce676f2a5bcc9651cef6e7956f05def-CDN/-w431t5/805012/9a9e1fae3639050b38ac467c3aa37e79/3abe50d469404b639745df44b51476b6/_/download/contextbatch/js/jira.browse.project,jira.view.issue,project.issue.navigator,jira.global,atl.general,-_super/batch.js?agile_global_admin_condition=true&jag=true&jira.create.linked.issue=true&locale=en-US&richediton=true","startTime":148.60000038146973,"connectEnd":148.60000038146973,"connectStart":148.60000038146973,"domainLookupEnd":148.60000038146973,"domainLookupStart":148.60000038146973,"fetchStart":148.60000038146973,"redirectEnd":0,"redirectStart":0,"requestStart":148.60000038146973,"responseEnd":408.30000019073486,"responseStart":408.30000019073486,"secureConnectionStart":148.60000038146973},{"duration":262.69999980926514,"initiatorType":"script","name":"https://jira.workterra.net/s/ecf7ec549751ae117b778f0525d6d371-CDN/-w431t5/805012/9a9e1fae3639050b38ac467c3aa37e79/4.1.5/_/download/resources/com.atlassian.plugins.atlassian-chaperone:hotspot-tour/hotspot-tour.js?batch=false&locale=en-US","startTime":148.9000005722046,"connectEnd":148.9000005722046,"connectStart":148.9000005722046,"domainLookupEnd":148.9000005722046,"domainLookupStart":148.9000005722046,"fetchStart":148.9000005722046,"redirectEnd":0,"redirectStart":0,"requestStart":148.9000005722046,"responseEnd":411.6000003814697,"responseStart":411.6000003814697,"secureConnectionStart":148.9000005722046},{"duration":263.1000003814697,"initiatorType":"script","name":"https://jira.workterra.net/s/6aa3fcf1fac5fd551eee0b69077524e6-CDN/-w431t5/805012/9a9e1fae3639050b38ac467c3aa37e79/aae1242f5fc81cc6a5bb8bc963ccda29/_/download/contextbatch/js/atl.global,-_super/batch.js?locale=en-US","startTime":149,"connectEnd":149,"connectStart":149,"domainLookupEnd":149,"domainLookupStart":149,"fetchStart":149,"redirectEnd":0,"redirectStart":0,"requestStart":149,"responseEnd":412.1000003814697,"responseStart":412.1000003814697,"secureConnectionStart":149},{"duration":263.4000005722046,"initiatorType":"script","name":"https://jira.workterra.net/s/d41d8cd98f00b204e9800998ecf8427e-CDN/-w431t5/805012/9a9e1fae3639050b38ac467c3aa37e79/1.0/_/download/batch/jira.webresources:calendar-en/jira.webresources:calendar-en.js","startTime":149.19999980926514,"connectEnd":149.19999980926514,"connectStart":149.19999980926514,"domainLookupEnd":149.19999980926514,"domainLookupStart":149.19999980926514,"fetchStart":149.19999980926514,"redirectEnd":0,"redirectStart":0,"requestStart":149.19999980926514,"responseEnd":412.6000003814697,"responseStart":412.6000003814697,"secureConnectionStart":149.19999980926514},{"duration":263.5,"initiatorType":"script","name":"https://jira.workterra.net/s/d41d8cd98f00b204e9800998ecf8427e-CDN/-w431t5/805012/9a9e1fae3639050b38ac467c3aa37e79/1.0/_/download/batch/jira.webresources:calendar-localisation-moment/jira.webresources:calendar-localisation-moment.js","startTime":149.4000005722046,"connectEnd":149.4000005722046,"connectStart":149.4000005722046,"domainLookupEnd":149.4000005722046,"domainLookupStart":149.4000005722046,"fetchStart":149.4000005722046,"redirectEnd":0,"redirectStart":0,"requestStart":149.4000005722046,"responseEnd":412.9000005722046,"responseStart":412.9000005722046,"secureConnectionStart":149.4000005722046},{"duration":263.69999980926514,"initiatorType":"script","name":"https://jira.workterra.net/s/ecf7ec549751ae117b778f0525d6d371-CDN/-w431t5/805012/9a9e1fae3639050b38ac467c3aa37e79/8.5.0/_/download/batch/com.atlassian.auiplugin:split_aui.pattern.label/com.atlassian.auiplugin:split_aui.pattern.label.js?locale=en-US","startTime":149.5,"connectEnd":149.5,"connectStart":149.5,"domainLookupEnd":149.5,"domainLookupStart":149.5,"fetchStart":149.5,"redirectEnd":0,"redirectStart":0,"requestStart":149.5,"responseEnd":413.19999980926514,"responseStart":413.19999980926514,"secureConnectionStart":149.5},{"duration":264.4000005722046,"initiatorType":"link","name":"https://jira.workterra.net/s/05c862146699bb029ceb0a489075e63b-CDN/-w431t5/805012/9a9e1fae3639050b38ac467c3aa37e79/bcd66e9a133a1b9f5fd14b56841e1c5b/_/download/contextbatch/css/jira.global.look-and-feel,-_super/batch.css","startTime":149.69999980926514,"connectEnd":0,"connectStart":0,"domainLookupEnd":0,"domainLookupStart":0,"fetchStart":149.69999980926514,"redirectEnd":0,"redirectStart":0,"requestStart":0,"responseEnd":414.1000003814697,"responseStart":0,"secureConnectionStart":0},{"duration":263.79999923706055,"initiatorType":"script","name":"https://jira.workterra.net/rest/api/1.0/shortcuts/805012/a664c2c06e52d83566c477b9899c262e/shortcuts.js?context=issuenavigation&context=issueaction","startTime":149.9000005722046,"connectEnd":149.9000005722046,"connectStart":149.9000005722046,"domainLookupEnd":149.9000005722046,"domainLookupStart":149.9000005722046,"fetchStart":149.9000005722046,"redirectEnd":0,"redirectStart":0,"requestStart":149.9000005722046,"responseEnd":413.69999980926514,"responseStart":413.69999980926514,"secureConnectionStart":149.9000005722046},{"duration":264.0999994277954,"initiatorType":"link","name":"https://jira.workterra.net/s/9095228fa10daa2d3e3d7d5760c95e91-CDN/-w431t5/805012/9a9e1fae3639050b38ac467c3aa37e79/72477c22780abda5f51fe696920d843f/_/download/contextbatch/css/com.atlassian.jira.projects.sidebar.init,-_super,-jira.view.issue,-project.issue.navigator/batch.css?jira.create.linked.issue=true&richediton=true","startTime":150.10000038146973,"connectEnd":0,"connectStart":0,"domainLookupEnd":0,"domainLookupStart":0,"fetchStart":150.10000038146973,"redirectEnd":0,"redirectStart":0,"requestStart":0,"responseEnd":414.19999980926514,"responseStart":0,"secureConnectionStart":0},{"duration":264.1000003814697,"initiatorType":"script","name":"https://jira.workterra.net/s/c19a1b46e985d7fb85efaf27c8febfdd-CDN/-w431t5/805012/9a9e1fae3639050b38ac467c3aa37e79/72477c22780abda5f51fe696920d843f/_/download/contextbatch/js/com.atlassian.jira.projects.sidebar.init,-_super,-jira.view.issue,-project.issue.navigator/batch.js?jira.create.linked.issue=true&locale=en-US&richediton=true","startTime":150.19999980926514,"connectEnd":150.19999980926514,"connectStart":150.19999980926514,"domainLookupEnd":150.19999980926514,"domainLookupStart":150.19999980926514,"fetchStart":150.19999980926514,"redirectEnd":0,"redirectStart":0,"requestStart":150.19999980926514,"responseEnd":414.30000019073486,"responseStart":414.30000019073486,"secureConnectionStart":150.19999980926514},{"duration":419,"initiatorType":"script","name":"https://jira.workterra.net/s/d41d8cd98f00b204e9800998ecf8427e-CDN/-w431t5/805012/9a9e1fae3639050b38ac467c3aa37e79/1.0/_/download/batch/jira.webresources:bigpipe-js/jira.webresources:bigpipe-js.js","startTime":151.19999980926514,"connectEnd":151.19999980926514,"connectStart":151.19999980926514,"domainLookupEnd":151.19999980926514,"domainLookupStart":151.19999980926514,"fetchStart":151.19999980926514,"redirectEnd":0,"redirectStart":0,"requestStart":151.19999980926514,"responseEnd":570.1999998092651,"responseStart":570.1999998092651,"secureConnectionStart":151.19999980926514}],"threshold":1000,"fetchStart":0,"domainLookupStart":0,"domainLookupEnd":0,"connectStart":0,"connectEnd":0,"requestStart":19,"responseStart":136,"responseEnd":137,"domLoading":145,"domInteractive":998,"domContentLoadedEventStart":998,"domContentLoadedEventEnd":1047,"domComplete":1497,"loadEventStart":1497,"loadEventEnd":1499,"userAgent":"Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; ClaudeBot/1.0; +claudebot@anthropic.com)","marks":[],"measures":[],"correlationId":"d71111288ca6df","effectiveType":"4g","downlink":10,"rtt":0,"serverDuration":78,"dbReadsTimeInMs":14,"dbConnsTimeInMs":16,"applicationHash":"156decd7d2b4272533aa6cefc8294af635e1da97","experiments":[]}}
Fix is verified on Production environment, working as expected. Closing the issue.