Uploaded image for project: 'WORKTERRA'
  1. WORKTERRA
  2. WT-5688

[Secure Test] Request Details of Get URL for viewing Benefit Descriptions are having parameters as plain text and using same URL plan descriptions can be accessed across company.

    Details

    • Type: Bug
    • Status: Closed
    • Priority: Medium
    • Resolution: Done
    • Affects Version/s: None
    • Fix Version/s: None
    • Component/s: None
    • Labels:
      None
    • Environment:
      Production
    • Module:
      BenAdmin - Security
    • Reported by:
      Harbinger
    • Item State:
      Production QA

      Description

      [Secure Test] Request Details of Get URL for viewing Benefit Descriptions are having parameters as plain text and using same URL plan descriptions can be accessed across company.

      Start Tamper Data plugin for viewing Request Details.

      1. Login as Admin to Company 2.
      2. Login as Employee to Company 1
      3. Traverse Employee Self Serve mode to Enroll now plans like Medical,Dental,Vision etc.
      4. Click on Benefit Description
      5. Go to Tamper Data and check for the Request Details. Refer Screen Shots for details.
      6. Copy the URL and paste it in the Admin user's session of company 2
      7. Using same URL plan descriptions can be accessed across company.

      Refer screenshots for details

        Attachments

          Activity

          Transition Time In Source Status Execution Times
          Vijayendra Shinde (Inactive) made transition -
          Open In Development
          7d 18h 13m 1
          Prasad Pise (Inactive) made transition -
          In LB Testing Reopen in Local
          8s 1
          Vijayendra Shinde (Inactive) made transition -
          Reopen in Local In Development
          10h 17m 1
          Prasad Pise (Inactive) made transition -
          In Development In LB Testing
          5d 18h 26m 2
          Prasad Pise (Inactive) made transition -
          In LB Testing Stage Testing
          1d 22h 59m 1
          Prasad Pise (Inactive) made transition -
          Stage Testing In Production Testing
          2d 17m 1
          Prasad Pise (Inactive) made transition -
          In Production Testing Production Complete
          21m 15s 1
          Priya Dhamande (Inactive) made transition -
          Production Complete Closed
          1h 17m 1

            People

            Assignee:
            rakeshr Rakesh Roy (Inactive)
            Reporter:
            prasadp Prasad Pise (Inactive)
            Votes:
            0 Vote for this issue
            Watchers:
            3 Start watching this issue

              Dates

              Created:
              Updated:
              Resolved: