Loading HuntDB...

User with single department permission can view applicant list of all department's

Medium
L
Lark Technologies
Submitted None

Team Summary

Official summary from Lark Technologies

An endpoint was discovered that did not properly check for user permissions which could have caused unauthorized access to view pending approval requests, email addresses, and phone numbers belonging to other departments. We thank @imran_nisar for reporting this to our team and confirming the resolution.

Reported by imran_nisar

Report Details

Additional information and metadata

State

Closed

Substate

Resolved

Submitted

Weakness

Privilege Escalation