User with single department permission can view applicant list of all department's
Medium
L
Lark Technologies
Submitted None
Team Summary
Official summary from Lark Technologies
An endpoint was discovered that did not properly check for user permissions which could have caused unauthorized access to view pending approval requests, email addresses, and phone numbers belonging to other departments. We thank @imran_nisar for reporting this to our team and confirming the resolution.
Actions:
Reported by
imran_nisar
Report Details
Additional information and metadata
State
Closed
Substate
Resolved
Submitted
Weakness
Privilege Escalation