#10 Bypassing authorization

Chiuso
aperto 5 anni fa da sindre · 0 commenti
sindre 5 anni fa ha commentato

User privilege validation is mostly performed on the client side. In this case it allows outside users without project access to perform task-deliveries and accept tasks. This must be done by sending a plain HTTP request instead of interacting through the client web page.

User privilege validation is mostly performed on the client side. In this case it allows outside users without project access to perform task-deliveries and accept tasks. This must be done by sending a plain HTTP request instead of interacting through the client web page.
sindre aggiunta alle pietre miliari Required fixes 5 anni fa
sindre added the
broken access control
label 5 anni fa
sindre added the
bug
label 5 anni fa
sindre added the
webpy
label 5 anni fa
Effettua l'accesso per partecipare alla conversazione.
Loading…
Annulla
Salva
Non ci sono ancora contenuti.