Uploaded image for project: 'WORKTERRA'
  1. WORKTERRA
  2. WT-4680

[Security Test] Postal Code and Work Phone fields can be manipulated by inserting invalid values from proxy tool.

    Details

    • Type: Bug
    • Status: Open
    • Priority: Medium
    • Resolution: Unresolved
    • Affects Version/s: None
    • Fix Version/s: None
    • Component/s: None
    • Labels:
    • Environment:
      Production
    • Bug Severity:
      Medium
    • Module:
      BenAdmin - Security
    • Reported by:
      Harbinger

      Description

      [Security Test] Postal Code and Work Phone fields can be manipulated by inserting invalid values from proxy tool.

      1. Login as Employee and traverse the self serve mode till Add beneficiary page
      2. Add/Update beneficiary details and enter the valid Postal Code and Work Phone
      3. Open Tamper Data tool and click on start Tamper
      4. Go to the Add/Update beneficiary page and save the beneficiary details.
      5. Click on Tamper Data button and Go to Tamper Data Post parameter page to insert invalid Postal COde and Work Phone.
      6. Click on OK button to fire the POST request again.
      7. Invalid data gets saved.

      Server Side input validations needs to be implemented throughout the workterra application.

        Attachments

          Activity

          prasadp Prasad Pise (Inactive) created issue -
          prasadp Prasad Pise (Inactive) made changes -
          Field Original Value New Value
          Description [Security Test] Postal Code and Work Phone fields can be manipulated by inserting invalid values from proxy tool.

          1. Login as Employee and traverse the self serve mode till Add beneficiary page
          2. Add/Update beneficiary details and enter the valid Postal Code and Work Phone
          3. Open Tamper Data tool and click on start Tamper
          4. Go to the Add/Update beneficiary page and save the beneficiary details.
          5. Click on Tamper Data button and Go to Tamper Data Post parameter page to insert invalid Postal COde and Work Phone.
          6. Click on OK button to fire the POST request again.
          7. Invalid data gets saved.
          [Security Test] Postal Code and Work Phone fields can be manipulated by inserting invalid values from proxy tool.

          1. Login as Employee and traverse the self serve mode till Add beneficiary page
          2. Add/Update beneficiary details and enter the valid Postal Code and Work Phone
          3. Open Tamper Data tool and click on start Tamper
          4. Go to the Add/Update beneficiary page and save the beneficiary details.
          5. Click on Tamper Data button and Go to Tamper Data Post parameter page to insert invalid Postal COde and Work Phone.
          6. Click on OK button to fire the POST request again.
          7. Invalid data gets saved.

          Server Side input validations needs to be implemented throughout the workterra application.
          rakeshr Rakesh Roy (Inactive) made changes -
          Module Parent values: BenAdmin(10100) Parent values: BenAdmin(10100)Level 1 values: Security(10112)
          prasadp Prasad Pise (Inactive) made changes -
          Severity Medium [ 13102 ]
          prasadp Prasad Pise (Inactive) made changes -
          Issue Category EBS [ 10350 ] Harbinger [ 10700 ]
          shyam.sharma shyam sharma (Inactive) made changes -
          Sprint WT Sprint 35 - Bugs [ 81 ]
          shyam.sharma shyam sharma (Inactive) made changes -
          Rank Ranked higher
          shyam.sharma shyam sharma (Inactive) made changes -
          Sprint WT Sprint 35 - Bugs [ 81 ]
          shyam.sharma shyam sharma (Inactive) made changes -
          Rank Ranked lower
          rakeshr Rakesh Roy (Inactive) made changes -
          Bug Severity Medium [ 16702 ]
          satyap Satya made changes -
          Labels Security
          satyap Satya made changes -
          Environment_New Production [ 18442 ]
          vijayendra Vijayendra Shinde (Inactive) made changes -
          Link This issue relates to DEV-13718 [ DEV-13718 ]

            People

            Assignee:
            samir Samir
            Reporter:
            prasadp Prasad Pise (Inactive)
            Votes:
            0 Vote for this issue
            Watchers:
            1 Start watching this issue

              Dates

              Created:
              Updated: