-
Type:
Bug
-
Status: Closed
-
Priority:
Medium
-
Resolution: Done
-
Affects Version/s: None
-
Fix Version/s: None
-
Component/s: Platform
-
Labels:None
-
Environment:QA
-
Module:Platform - Security
-
Reported by:Harbinger
-
Item State:Production Complete
-
Issue Importance:Must Have
-
Sprint:Bugs-Must Fix- Pilot July2016
1] Login to the application on local environment using following URL:
https://wt-stage.harbinger.in
2] From Home page search and select a company for which testing needs to be carried out using "Search Company" section.
3] Click on "Ben Admin" menu.
4] Click on "Customizer" icon from left navigation menu.
5] Click on "Rates" link which is submenu of "Customizer", user gets navigate to "Rates" details page.
6] Click on "Import" button displaying at top right hand side of the "Rates" page, the "Rate Import" window gets poped up, click on “Add New Rate” tab.
7] Browse the file new rate file.
8] Now browse a image or .exe/.dll file with whose extension is tampered. (i.e. extension changed to .xlsm/.xlsx)
9] Click on "Upload" button.
Actual Result:
Application is allowing to upload such files and when user click on “Import Rate” button the Server error is displaying.
Expected Result:
Not supported extensions files (.txt, .pdf, image files, executable files etc) should not be get uploaded after tampering the extension.
Field | Original Value | New Value |
---|---|---|
Assignee | Sujit Chopade [ sujit.chopade ] | Harshawardhan Phalake [ harshawardhan ] |
Component/s | Platform [ 10006 ] | |
Component/s | Xpress [ 10200 ] | |
Module | Parent values: Xpress(11100) | Parent values: Platform(10106)Level 1 values: Security(10115) |
Assignee | Harshawardhan Phalake [ harshawardhan ] | Satya [ ID10004 ] |
Assignee | Satya [ ID10004 ] | Samir [ samir ] |
Issue Importance | Must Have [ 11800 ] |
Item State | Parent values: LB QA(10201) | Parent values: Development(10200)Level 1 values: Development Backlog(10205) |
Assignee | Samir [ samir ] | Vijayendra Shinde [ ID10506 ] |
Status | Open [ 1 ] | In Development [ 10007 ] |
Item State | Parent values: Development(10200)Level 1 values: Development Backlog(10205) | Parent values: Development(10200)Level 1 values: In Progress(10206) |
Item State | Parent values: Development(10200)Level 1 values: In Progress(10206) | Parent values: Development(10200)Level 1 values: Ready for Local Testing(10209) |
Item State | Parent values: Development(10200)Level 1 values: Ready for Local Testing(10209) | Parent values: LB QA(10201) |
Status | In Development [ 10007 ] | Local Testing [ 10200 ] |
Item State | Parent values: LB QA(10201) | Parent values: Development(10200)Level 1 values: Ready for Local Testing(10209) |
Status | Local Testing [ 10200 ] | Reopen in Local [ 10018 ] |
Status | Reopen in Local [ 10018 ] | In Development [ 10007 ] |
Item State | Parent values: Development(10200)Level 1 values: Ready for Local Testing(10209) | Parent values: LB QA(10201)Level 1 values: LB Deployed(11600) |
Assignee | Vijayendra Shinde [ ID10506 ] | Kunal Kedari [ kunal.kedari ] |
Status | In Development [ 10007 ] | Local Testing [ 10200 ] |
Assignee | Kunal Kedari [ kunal.kedari ] | Vijayendra Shinde [ ID10506 ] |
Status | Local Testing [ 10200 ] | Reopen in Local [ 10018 ] |
Attachment | UploadPDF.jpg [ 20002 ] |
Status | Reopen in Local [ 10018 ] | In Development [ 10007 ] |
Assignee | Vijayendra Shinde [ ID10506 ] | Kunal Kedari [ kunal.kedari ] |
Status | In Development [ 10007 ] | Local Testing [ 10200 ] |
Status | Local Testing [ 10200 ] | Reopen in Local [ 10018 ] |
Assignee | Kunal Kedari [ kunal.kedari ] | Vijayendra Shinde [ ID10506 ] |
Status | Reopen in Local [ 10018 ] | In Development [ 10007 ] |
Assignee | Vijayendra Shinde [ ID10506 ] | Kunal Kedari [ kunal.kedari ] |
Sprint | Bugs-Must Fix- Pilot July2016 [ 16 ] |
Rank | Ranked lower |
Item State | Parent values: LB QA(10201)Level 1 values: LB Deployed(11600) | Parent values: LB QA(10201)Level 1 values: In Testing(10210) |
Status | In Development [ 10007 ] | Local Testing [ 10200 ] |
Attachment | QA_Checklist.xlsx [ 21711 ] |
Assignee | Kunal Kedari [ kunal.kedari ] | Rajendra Joshi [ rajendraj ] |
Assignee | Rajendra Joshi [ rajendraj ] | Kunal Kedari [ kunal.kedari ] |
Attachment | QA_Checklist.xlsx [ 21711 ] |
Attachment | QAChecklist_MIME.xlsx [ 21907 ] |
Assignee | Kunal Kedari [ kunal.kedari ] | Vijayendra Shinde [ ID10506 ] |
Assignee | Vijayendra Shinde [ ID10506 ] | Kunal Kedari [ kunal.kedari ] |
Attachment | AfterFixVerification_QAChecklist_MIME.xlsx [ 21910 ] |
Item State | Parent values: LB QA(10201)Level 1 values: In Testing(10210) | Parent values: LB QA(10201)Level 1 values: Ready for Stage(10213) |
QA | Kunal Kedari [ kunal.kedari ] |
Production Due Date | 21/Jul/2016 | |
Stage Due Date | 18/Jul/16 [ 2016-07-18 ] |
Developer | Vijayendra Shinde [ ID10506 ] |
Item State | Parent values: LB QA(10201)Level 1 values: Ready for Stage(10213) | Parent values: Stage QA(10202)Level 1 values: Stage Deployed(11602) |
Item State | Parent values: Stage QA(10202)Level 1 values: Stage Deployed(11602) | Parent values: Stage QA(10202)Level 1 values: In Testing(10214) |
Assignee | Kunal Kedari [ kunal.kedari ] | Vijayendra Shinde [ ID10506 ] |
Attachment | RateImportErrorForXlsFile.jpg [ 22104 ] |
Attachment | TestRateUsedForTesting.xls [ 22105 ] |
Status | Local Testing [ 10200 ] | Reopen in Local [ 10018 ] |
Item State | Parent values: Stage QA(10202)Level 1 values: In Testing(10214) | Parent values: Stage QA(10202)Level 1 values: Re-open(10216) |
Status | Reopen in Local [ 10018 ] | In Development [ 10007 ] |
Status | In Development [ 10007 ] | Local Testing [ 10200 ] |
Status | Local Testing [ 10200 ] | Stage Testing [ 10201 ] |
Resolution | Unresolved [ 10200 ] | |
Status | Stage Testing [ 10201 ] | Reopen in Stage [ 10023 ] |
Attachment | screenshot-1.png [ 23037 ] |
Item State | Parent values: Stage QA(10202)Level 1 values: Re-open(10216) | Parent values: Stage QA(10202)Level 1 values: Stage Deployed(11602) |
Assignee | Vijayendra Shinde [ ID10506 ] | Kunal Kedari [ kunal.kedari ] |
Status | Reopen in Stage [ 10023 ] | In Development [ 10007 ] |
Status | In Development [ 10007 ] | Local Testing [ 10200 ] |
Status | Local Testing [ 10200 ] | Stage Testing [ 10201 ] |
Item State | Parent values: Stage QA(10202)Level 1 values: Stage Deployed(11602) | Parent values: Stage QA(10202)Level 1 values: In Testing(10214) |
Production Due Date | 21/Jul/2016 | 04/Aug/2016 |
Item State | Parent values: Stage QA(10202)Level 1 values: In Testing(10214) | Parent values: Stage QA(10202)Level 1 values: Ready for Production(10217) |
Item State | Parent values: Stage QA(10202)Level 1 values: Ready for Production(10217) | Parent values: Stage QA(10202)Level 1 values: Production Deployment on Hold(10224) |
Item State | Parent values: Stage QA(10202)Level 1 values: Production Deployment on Hold(10224) | Parent values: Production QA(10203)Level 1 values: Production Deployed(10221) |
Item State | Parent values: Production QA(10203)Level 1 values: Production Deployed(10221) | Parent values: Production QA(10203)Level 1 values: In Testing(10218) |
Status | Stage Testing [ 10201 ] | Production Testing [ 10202 ] |
Resolution | Unresolved [ 10200 ] | Fixed [ 1 ] |
Status | Production Testing [ 10202 ] | Production Complete [ 10028 ] |
Status | Production Complete [ 10028 ] | Closed [ 6 ] |
Item State | Parent values: Production QA(10203)Level 1 values: In Testing(10218) | Parent values: Production Complete(10222) |
Environment_New | LB [ 18444 ] |
Transition | Time In Source Status | Execution Times |
---|
|
74d 4h 32m | 1 |
|
31d 13h 3m | 4 |
|
8d 6h 33m | 4 |
|
2s | 1 |
|
16h 42m | 1 |
|
8d 7h 19m | 6 |
|
6s | 2 |
|
36d 21h 24m | 1 |
|
7s | 1 |
|
2s | 1 |
We have logged same issue earlier as well (Track Ticket #8569) as a part of security testing, at that time it was fixed on Local, Stage and Production environments, but it seems that somehow it gets open again. User should not be able to upload a non-supported extension file by any mean from application.