-
Type:
Bug
-
Status: Closed
-
Priority:
High
-
Resolution: Cancelled
-
Affects Version/s: None
-
Fix Version/s: None
-
Component/s: Platform
-
Labels:None
-
Environment:Production
-
Module:Platform - Security
-
Reported by:Harbinger
[Security Test] Date fields validations are not present on server side due to which it is possible to manipulate dates in application.
Test Environment: Production
Tools Used : ZAP, Tamper Data
Browser: Chrome, Firefox
1. Login as Admin
2. Go to a test company
2. Go to Benefit Type Builder
3. Select any existing benefit type
4. Update the Benefit Start date and End Date using proxy tool like ZAP/Tamper Data through post request.
5. Check for the updated dates on form.
We have altered the Start Date,End Date, Plan Effective Date and Plan termination date for 'Basic Life' benefit type. PFA screenshots.
*
This can be possible in any date field of entire workterra application and can impact on existing as well as future data.*
Expected Result:
[Security Test] Date fields validations on server side needs to be implemented throughout the application.
This is getting considered in UI Refresh, hence closing this separate ticket.
Regards,
Satya Prakash
Cc: Vijayendra Shinde Rakesh Roy Samir Vijay Siddha