-
Type:
Bug
-
Status: Closed
-
Priority:
Medium
-
Resolution: Done
-
Affects Version/s: None
-
Fix Version/s: None
-
Component/s: None
-
Labels:None
-
Environment:Production
-
Module:BenAdmin - Security
-
Reported by:Harbinger
-
Item State:Production QA
[Secure Test] Request Details of Get URL for viewing Benefit Descriptions are having parameters as plain text and using same URL plan descriptions can be accessed across company.
Start Tamper Data plugin for viewing Request Details.
1. Login as Admin to Company 2.
2. Login as Employee to Company 1
3. Traverse Employee Self Serve mode to Enroll now plans like Medical,Dental,Vision etc.
4. Click on Benefit Description
5. Go to Tamper Data and check for the Request Details. Refer Screen Shots for details.
6. Copy the URL and paste it in the Admin user's session of company 2
7. Using same URL plan descriptions can be accessed across company.
Refer screenshots for details
HI Vijayendra Shinde
Issue verified on Stage after patch deployment. I tried by removing the value of parameter "encryptedCompanyID" and hit Enter key. No Plan details displayed.
User is asked to click on "Return to home page" button.
Thanks
CC: SamirVijay SiddhaRakesh Roy