Uploaded image for project: 'WORKTERRA'
  1. WORKTERRA
  2. WT-4794

[Security Test] Date fields validations are not present on server side due to which it is possible to manipulate any dates in application.

    Details

    • Type: Bug
    • Status: Closed
    • Priority: High
    • Resolution: Cancelled
    • Affects Version/s: None
    • Fix Version/s: None
    • Component/s: Platform
    • Labels:
      None
    • Environment:
      Production
    • Module:
      Platform - Security
    • Reported by:
      Harbinger

      Description

      [Security Test] Date fields validations are not present on server side due to which it is possible to manipulate dates in application.
      Test Environment: Production
      Tools Used : ZAP, Tamper Data
      Browser: Chrome, Firefox

      1. Login as Admin
      2. Go to a test company
      2. Go to Benefit Type Builder
      3. Select any existing benefit type
      4. Update the Benefit Start date and End Date using proxy tool like ZAP/Tamper Data through post request.
      5. Check for the updated dates on form.
      We have altered the Start Date,End Date, Plan Effective Date and Plan termination date for 'Basic Life' benefit type. PFA screenshots.
      *
      This can be possible in any date field of entire workterra application and can impact on existing as well as future data.*

      Expected Result:
      [Security Test] Date fields validations on server side needs to be implemented throughout the application.

        Attachments

          Activity

          Hide
          admin01 admin added a comment -

          This is getting considered in UI Refresh, hence closing this separate ticket.

          Regards,
          Satya Prakash

          Cc: Vijayendra Shinde Rakesh Roy Samir Vijay Siddha

          Show
          admin01 admin added a comment - This is getting considered in UI Refresh, hence closing this separate ticket. Regards, Satya Prakash Cc: Vijayendra Shinde Rakesh Roy Samir Vijay Siddha

            People

            Assignee:
            samir Samir
            Reporter:
            prasadp Prasad Pise (Inactive)
            Votes:
            0 Vote for this issue
            Watchers:
            2 Start watching this issue

              Dates

              Created:
              Updated:
              Resolved: