Globalshala / Eval-Bridge-bugs

In the Repository, we will add the bugs related to eval bridge system
0 stars 1 forks source link

Access to Admin Modules via URL Manipulation #324

Open Adnan-shariff opened 2 weeks ago

Adnan-shariff commented 2 weeks ago

Describe the bug Team Lead and Moderator accounts can access Admin-only modules by directly entering specific URLs, allowing them to bypass access restrictions.

Moderator: http://13.127.150.18/appid-to-specific-user http://13.127.150.18/create-user

Team Lead: http://13.127.150.18/appid-to-specific-user, http://13.127.150.18/reassign-app-user, http://13.127.150.18/grade-scales, http://13.127.150.18/create-user

Steps to reproduce

  1. Log in as a Team Lead or Moderator.
  2. Directly enter any of the URLs listed above.
  3. Expected Behavior
  4. Only Admin accounts should access these URLs.

Expected Behavior Only Admin accounts should access these URLs.

Actual Behavior The Moderator account accesses two modules, while the Team Lead account accesses multiple Admin-only modules.

Screenshots 2024-11-11 11_43_41-Window 2024-11-11 11_44_03-Window 2024-11-11 11_45_47- 2024-11-11 11_46_06- 2024-11-11 11_58_35-2024-11-11 11_21_12-Window 2024-11-11 11_59_10-2024-11-11 11_22_13- 2024-11-11 11_59_38-2024-11-11 11_22_42-Window 2024-11-11 12_00_06-2024-11-11 11_22_52- 2024-11-11 12_00_28-2024-11-11 11_23_29-Window 2024-11-11 12_01_15- 2024-11-11 12_01_28-