Uploaded image for project: 'WORKTERRA'
  1. WORKTERRA
  2. WT-4794

[Security Test] Date fields validations are not present on server side due to which it is possible to manipulate any dates in application.

    Details

    • Type: Bug
    • Status: Closed
    • Priority: High
    • Resolution: Cancelled
    • Affects Version/s: None
    • Fix Version/s: None
    • Component/s: Platform
    • Labels:
      None
    • Environment:
      Production
    • Module:
      Platform - Security
    • Reported by:
      Harbinger

      Description

      [Security Test] Date fields validations are not present on server side due to which it is possible to manipulate dates in application.
      Test Environment: Production
      Tools Used : ZAP, Tamper Data
      Browser: Chrome, Firefox

      1. Login as Admin
      2. Go to a test company
      2. Go to Benefit Type Builder
      3. Select any existing benefit type
      4. Update the Benefit Start date and End Date using proxy tool like ZAP/Tamper Data through post request.
      5. Check for the updated dates on form.
      We have altered the Start Date,End Date, Plan Effective Date and Plan termination date for 'Basic Life' benefit type. PFA screenshots.
      *
      This can be possible in any date field of entire workterra application and can impact on existing as well as future data.*

      Expected Result:
      [Security Test] Date fields validations on server side needs to be implemented throughout the application.

        Attachments

          Activity

          prasadp Prasad Pise (Inactive) created issue -
          rakeshr Rakesh Roy (Inactive) made changes -
          Field Original Value New Value
          Component/s BenAdmin [ 10000 ]
          rakeshr Rakesh Roy (Inactive) made changes -
          Component/s Platform [ 10006 ]
          Component/s BenAdmin [ 10000 ]
          satyap Satya made changes -
          Module Parent values: BenAdmin(10100) Parent values: Platform(10106)Level 1 values: Security(10115)
          prasadp Prasad Pise (Inactive) made changes -
          Severity Complex [ 13103 ]
          prasadp Prasad Pise (Inactive) made changes -
          Issue Category EBS [ 10350 ] Harbinger [ 10700 ]
          admin01 admin made changes -
          Status Open [ 1 ] In Development [ 10007 ]
          admin01 admin made changes -
          Resolution Won't Do [ 10001 ]
          Status In Development [ 10007 ] Rejected [ 10004 ]
          admin01 admin made changes -
          Status Rejected [ 10004 ] Closed [ 6 ]
          satyap Satya made changes -
          Environment_New Production [ 18442 ]
          vijayendra Vijayendra Shinde (Inactive) made changes -
          Link This issue relates to DEV-13718 [ DEV-13718 ]

            People

            Assignee:
            samir Samir
            Reporter:
            prasadp Prasad Pise (Inactive)
            Votes:
            0 Vote for this issue
            Watchers:
            2 Start watching this issue

              Dates

              Created:
              Updated:
              Resolved: