Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

fix potential IDOR on changeStatusParticipant route #8

Open
wants to merge 1 commit into
base: dev
Choose a base branch
from

Conversation

akbarmridho
Copy link

Sudah dicek semua routes yang memiliki potensi IDOR vulnerability. Secara umum kasus IDOR vulnerability sudah ditangani dengan pemeriksaan kesesuaian teamID dan participantID utk role Team. Namun, ada satu route yang sepertinya terlewat pengecekannya

@akbarmridho
Copy link
Author

Satu lagi, aku liat di endpoint login sebagai admin error salah username dan password pesannya spesifik (Password salah, username salah), bukan (password atau username salah). Itu memang sengaja atau bagaimana kak?

@samuelswandi
Copy link
Collaborator

kayanya emang sengaja, karena yang nanti login admin juga cuman internal, jadi dgn lbh verbose lbh gampang debugnya. Nice question @akbarmridho

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants