Uploaded image for project: 'WORKTERRA'
  1. WORKTERRA
  2. WT-5525

Login page should allow single quote in User name

    Details

    • Type: Enhancement
    • Status: Closed
    • Priority: Medium
    • Resolution: Done
    • Affects Version/s: None
    • Fix Version/s: None
    • Component/s: Platform
    • Labels:
      None
    • Module:
      Platform
    • Reported by:
      Support
    • Item State:
      Production Complete - Closed
    • Issue Importance:
      Must Have

      Description

      UHC requires single quotes allowed in username of login page.

        Attachments

        1. Stage_pass.png
          Stage_pass.png
          240 kB
        2. Stage_Pass2.png
          Stage_Pass2.png
          299 kB
        3. WT_5525_SQLInjectionTest.xls
          70 kB

          Issue Links

            Activity

            Hide
            vijayendra Vijayendra Shinde (Inactive) added a comment -

            We need to verify all logins for this fix to ensure logins on production.

            Again, this fix needs to be tested for Security of Blind SQL injection.

            Show
            vijayendra Vijayendra Shinde (Inactive) added a comment - We need to verify all logins for this fix to ensure logins on production. Again, this fix needs to be tested for Security of Blind SQL injection.
            Hide
            vijayendra Vijayendra Shinde (Inactive) added a comment -

            Please check this fix after patch deployment

            Show
            vijayendra Vijayendra Shinde (Inactive) added a comment - Please check this fix after patch deployment
            Hide
            rakeshr Rakesh Roy (Inactive) added a comment -

            Prasad Pise Please chech security point.
            Rashmita Dudhe Test this after deployment.

            Show
            rakeshr Rakesh Roy (Inactive) added a comment - Prasad Pise Please chech security point. Rashmita Dudhe Test this after deployment.
            Hide
            rashmita.dudhe Rashmita Dudhe (Inactive) added a comment -

            Verified on LB environment consider below scenario.

            1]Import Employee with single quote Email address, name
            2]Login to the system with generated User name like o'donald.test121172
            3]adding employee through UI
            4] also login to the system with generated user name.

            Working fine.

            Show
            rashmita.dudhe Rashmita Dudhe (Inactive) added a comment - Verified on LB environment consider below scenario. 1]Import Employee with single quote Email address, name 2]Login to the system with generated User name like o'donald.test121172 3]adding employee through UI 4] also login to the system with generated user name. Working fine.
            Hide
            rashmita.dudhe Rashmita Dudhe (Inactive) added a comment -

            Verified on Stage environment consider below scenario.
            1]Import Employee with single quote Email address, name
            2]Login to the system with generated User name like o'donald.test121172
            3]adding employee through UI
            4] also login to the system with generated user name.
            Working fine.

            Show
            rashmita.dudhe Rashmita Dudhe (Inactive) added a comment - Verified on Stage environment consider below scenario. 1]Import Employee with single quote Email address, name 2]Login to the system with generated User name like o'donald.test121172 3]adding employee through UI 4] also login to the system with generated user name. Working fine.
            Hide
            prasadp Prasad Pise (Inactive) added a comment -

            Verified issue on Stage and Production environment for "User Name" field on login page. Tried with various SQL injections of different Payloads/inputs. No vulnerability found till now. WT_5525_SQLInjectionTest.xls

            Show
            prasadp Prasad Pise (Inactive) added a comment - Verified issue on Stage and Production environment for "User Name" field on login page. Tried with various SQL injections of different Payloads/inputs. No vulnerability found till now. WT_5525_SQLInjectionTest.xls
            Hide
            rashmita.dudhe Rashmita Dudhe (Inactive) added a comment -

            Verified on Production environment consider below scenario.
            1]Import Employee with single quote Email address, name
            2]Login to the system with generated User name like o'donald.test121172
            3]adding employee through UI
            4] also login to the system with generated user name.
            Working fine.

            Show
            rashmita.dudhe Rashmita Dudhe (Inactive) added a comment - Verified on Production environment consider below scenario. 1]Import Employee with single quote Email address, name 2]Login to the system with generated User name like o'donald.test121172 3]adding employee through UI 4] also login to the system with generated user name. Working fine.

              People

              Assignee:
              rashmita.dudhe Rashmita Dudhe (Inactive)
              Reporter:
              vijayendra Vijayendra Shinde (Inactive)
              Developer:
              Vijayendra Shinde (Inactive)
              Votes:
              0 Vote for this issue
              Watchers:
              4 Start watching this issue

                Dates

                Created:
                Updated:
                Resolved:
                Code Review Date: