Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Webforms are a huge risk. #1070

Open
ajiragroup opened this issue Oct 17, 2024 · 0 comments
Open

Webforms are a huge risk. #1070

ajiragroup opened this issue Oct 17, 2024 · 0 comments
Labels
bug Something isn't working

Comments

@ajiragroup
Copy link

I just checked all default web-forms.

If student:
domain.com/edit-profile takes me to : /edit-profile/new and I can fill up anyone's information.
image

domain.com/update-profile takes me to /edit-profile/new. Same as above.

/job-opportunity : I can create a job opportunity as a student. Its a good thing that company email address couldnot be set by student. so form does not get submitted. But even a system manager cannot set a company email from the same url.
image

student can add a new batch:
image

As a system manager

/update-profile will take me to : /edit-profile/[email protected] . This email address is of another user (course creator, etc)
/edit-profile will take me to : /edit-profile/[email protected] .

Please solve these vulnerabilities asap.

@ajiragroup ajiragroup added the bug Something isn't working label Oct 17, 2024
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
bug Something isn't working
Projects
None yet
Development

No branches or pull requests

1 participant