Loading HuntDB...

[EE] change the author of post using the author_id

Low
E
ExpressionEngine
Submitted None

Team Summary

Official summary from ExpressionEngine

@flex0geek discovered that users with permission to edit entries in the control panel could manipulate the form or POST submission and set an invalid author as the author of that entry. @flex0geek gave a detailed report with step-by-step instructions for replicating and screen captures of a their results, enabling a speedy resolution to the issue, which was to add additional validation on submission so that the new author would only be accepted if that author is allowed to be an author of the entry.

Reported by flex0geek

Report Details

Additional information and metadata

State

Closed

Substate

Resolved

Submitted

Weakness

Insecure Direct Object Reference (IDOR)