[EE] change the author of post using the author_id
Low
E
ExpressionEngine
Submitted None
Team Summary
Official summary from ExpressionEngine
@flex0geek discovered that users with permission to edit entries in the control panel could manipulate the form or POST submission and set an invalid author as the author of that entry. @flex0geek gave a detailed report with step-by-step instructions for replicating and screen captures of a their results, enabling a speedy resolution to the issue, which was to add additional validation on submission so that the new author would only be accepted if that author is allowed to be an author of the entry.
Actions:
Reported by
flex0geek
Report Details
Additional information and metadata
State
Closed
Substate
Resolved
Submitted
Weakness
Insecure Direct Object Reference (IDOR)