Santandersecurityresearch/asvs

Changing existing user to another reveals projects

NoobieDog opened this issue · 1 comments

in this case we have two users, notadmin and administrator

notadmin has 4 projects, adminstrator has 1

Screenshot (171)

when changing this username to another (case insensitive) (if an user with the exact username exists, see other bug, however if one character is changed case, this bug works)

Screenshot (172)

Once changed, the other user can see the emulated users projects

Screenshot (173)