You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Describe the bug
The bug is achieved via changing the cookie info giving the user permission to see Admin settings. Making possible user exfil Google ID, Github Client ID, Client Secret and even create links for register
To Reproduce
Steps to reproduce the behavior:
Go to the 'Application' tab in chrome dev tools or similar in your browser choice
Click on 'local storage'
Edit the cookie 'VOCECHAT_LOGIN_USER'
Set the "is_admin" to true
Expected behavior
Well, in a perfect and secure condition, nothing should appear, but on this case, the admin configuration settings was visible to me.
Screenshots
Desktop (please complete the following information):
OS: [Windows 11]
Browser [Chrome]
Server Version [v0.3.8]
Client Version [v0.7.42]
Server running on: [Mint 21]
Misc..
User can also check License, as I reported minutes ago. Issue #212
The text was updated successfully, but these errors were encountered:
Describe the bug
The bug is achieved via changing the cookie info giving the user permission to see Admin settings. Making possible user exfil Google ID, Github Client ID, Client Secret and even create links for register
To Reproduce
Steps to reproduce the behavior:
Expected behavior
Well, in a perfect and secure condition, nothing should appear, but on this case, the admin configuration settings was visible to me.
Screenshots
Desktop (please complete the following information):
Misc..
User can also check License, as I reported minutes ago. Issue #212
The text was updated successfully, but these errors were encountered: