Lucene search

K
huntrShubh123-tri4A1723E9-5BC4-4C4B-BCEB-1C45964CC71D
HistoryFeb 23, 2022 - 12:52 p.m.

Improper Access Control

2022-02-2312:52:57
shubh123-tri
www.huntr.dev
14

0.001 Low

EPSS

Percentile

37.2%

Description

It was found that if a user is not having access to the requested items module, a normal user with no access can still access and view the requested content.

It is a more detailed explanation of the given report where it was marked as invalid :
https://huntr.dev/bounties/783cfb0c-7e4d-4fdd-86c6-bd92743aee41/

Proof of Concept

  1. Create two users, one admin and one normal user(Only give view accessories access to the normal user)
  2. In the screenshot, you can see the normal user is not having access to the requested module.
  3. But with forced browsing, we can clearly see that the normal user can access the requested module.

Screenshots

Accessories view permission to normal user

alt text

alt text

Normal user view requested items

alt text

Impact

This vulnerability will help an attacker view restricted content.

0.001 Low

EPSS

Percentile

37.2%

Related for 4A1723E9-5BC4-4C4B-BCEB-1C45964CC71D