Lucene search

K
huntrShubh123-triBFFFAE58-B3CD-4E0E-B1F2-3DB387A22C3D
HistoryFeb 03, 2022 - 12:31 p.m.

Business Logic Errors in publify/publify

2022-02-0312:31:50
shubh123-tri
www.huntr.dev
8
business logic errors
publify
article privacy
bug bounty

EPSS

0.002

Percentile

53.5%

Description

It was found that if a user tries to create an article, and want to make that article private, the functionality is not working.

Proof of Concept

  1. Create an article
  2. Click on publish and you will see the option to visibility to make it private, but functionality is not designed properly.

Impact

This will lead in making every article public which a user does not want to disclose.

EPSS

0.002

Percentile

53.5%

Related for BFFFAE58-B3CD-4E0E-B1F2-3DB387A22C3D