#10 Bypassing authorization

Fermé
créé il y a 5 ans par sindre · 0 commentaires
sindre a commenté il y a 5 ans

User privilege validation is mostly performed on the client side. In this case it allows outside users without project access to perform task-deliveries and accept tasks. This must be done by sending a plain HTTP request instead of interacting through the client web page.

User privilege validation is mostly performed on the client side. In this case it allows outside users without project access to perform task-deliveries and accept tasks. This must be done by sending a plain HTTP request instead of interacting through the client web page.
sindre a ajouté cela au jalon Required fixes il y a 5 ans
sindre a ajouté l'étiquette
broken access control
il y a 5 ans
sindre a ajouté l'étiquette
bug
il y a 5 ans
sindre a ajouté l'étiquette
webpy
il y a 5 ans
Connectez-vous pour rejoindre cette conversation.
Chargement…
Annuler
Enregistrer
Il n'existe pas encore de contenu.