Improper Authorization in imran300/inventory
Valid
Reported on
Sep 4th 2021
✍️ Description
A General manager user can edit/add other group PERMISSIONS LIST
with IDOR.
🕵️♂️ Proof of Concept
go to this url when logging in as a General manager.
http://localhost:8000/inventory/index.php/generals/add_group
and then you can see that Permissions can be bypassed.
💥 Impact
This vulnerability is capable of change the group permissions with IDOR.
Occurrences
We have contacted a member of the
imran300/inventory
team and are waiting to hear back
2 years ago
I didn't change the default Group permissions and also check them to didn't have the desired permissions.
to join this conversation