Edit Policy restriction does not prevent comments.
Medium
P
Phabricator
Submitted None
Actions:
Reported by
rhinosf1
Vulnerability Details
Technical details and impact analysis
- Change the edit policy of a Maniphest Task
- Attempt to comment on the the task with a user who doesn't have access
## Impact
Given a few users I spoke to believe restricting the edit policy blocks comments, This allows an underpriveleged user to gain access to carry out a restrcited action.
(Mongoose)
Report Details
Additional information and metadata
State
Closed
Substate
Informative
Submitted
Weakness
Improper Access Control - Generic