Privilege escalation allows to use iframe functionality w/o upgrade
I
Infogram
Submitted None
Actions:
Reported by
muon4
Vulnerability Details
Technical details and impact analysis
Hello team!
I've found a privilege escalation issue which allows to set iframes to the projects w/o upgrading.
### Steps to reproduce
- Login
- Navigate to the project
- Choose `integrations` and click the `IFrame`
- See that you'll get `upgrade now` notification
{F501019}
- Inspect the page with developer tool and choose the `upgrade` from `IFrame` icon
- Delete the `data-upgrade="true"` part
{F501023}
- Click the `IFrame` and see that you are able to add iframe to the page w/o upgrade
{F501024}
If you need any information please let me know.
Cheers!
## Impact
Users can use functionalities without paying
Report Details
Additional information and metadata
State
Closed
Substate
Resolved
Submitted
Weakness
Privilege Escalation