pantsel / konga

More than just another GUI to Kong Admin API
MIT License
4.31k stars 828 forks source link

it was possible for a basic user to takeover any account using the ID Parameter. #764

Open salmankhwaja opened 2 years ago

salmankhwaja commented 2 years ago

it was possible for a basic user to takeover any account using the ID Parameter.

How to Reproduce -Edit the GET request -Manipulate the User ID -For further clarification, please follow the evidences 1 2 3 4 5 6

Techbrunch commented 1 year ago

I confirm that a non admin user can edit the profile of other users but the impact is limited since there are no specific access control linked to a user.