-
Type:
Bug
-
Status: Open
-
Priority:
Medium
-
Resolution: Unresolved
-
Affects Version/s: None
-
Fix Version/s: None
-
Component/s: None
-
Labels:
-
Environment:Production
-
Bug Severity:Low
-
Module:BenAdmin - Security
-
Reported by:Harbinger
[Security Test]
{Insecure Input Validation}In Employee Self Serve Mode, user is allowed to enter any data/ special characters like <,>,',-,* in Select Beneficiary (Trust - Trust Name) which cause application to throw Server Error.
Input validations needs to be implemented to avoid server errors because of any Malicious activity.
Field | Original Value | New Value |
---|---|---|
Summary | [Security Test] {Insecure Input Validation} In Employee Self Serve Mode, user is allowed to enter any data/ special characters like <,>,',-,* in Select Beneficiary (Trust - Trust Name) which cause application to throw Server Error. | [Security Test] {Server Side Input Validation} In Employee Self Serve Mode, user is allowed to enter any data/ special characters like <,>,',-,* in Select Beneficiary (Trust - Trust Name) which cause application to throw Server Error. |
Module | Parent values: BenAdmin(10100) | Parent values: BenAdmin(10100)Level 1 values: Security(10112) |
Severity | Complex [ 13103 ] |
Issue Category | EBS [ 10350 ] | Harbinger [ 10700 ] |
Bug Severity | Low [ 16703 ] |
Labels | Security |
Environment_New | Production [ 18442 ] |
Link | This issue relates to DEV-13718 [ DEV-13718 ] |