#10 Bypassing authorization

Stängd
öppnade 5 år sedan av sindre · 0 kommentarer
sindre kommenterad 5 år sedan

User privilege validation is mostly performed on the client side. In this case it allows outside users without project access to perform task-deliveries and accept tasks. This must be done by sending a plain HTTP request instead of interacting through the client web page.

User privilege validation is mostly performed on the client side. In this case it allows outside users without project access to perform task-deliveries and accept tasks. This must be done by sending a plain HTTP request instead of interacting through the client web page.
sindre lade till denna till milstolpe Required fixes 5 år sedan
sindre added the
broken access control
label 5 år sedan
sindre added the
bug
label 5 år sedan
sindre added the
webpy
label 5 år sedan
Logga in för att delta i denna konversation.
Laddar…
Avbryt
Spara
Det finns inget innehåll än.