Loading HuntDB...

Edit Policy restriction does not prevent comments.

Medium
P
Phabricator
Submitted None
Reported by rhinosf1

Vulnerability Details

Technical details and impact analysis

Improper Access Control - Generic
- Change the edit policy of a Maniphest Task - Attempt to comment on the the task with a user who doesn't have access ## Impact Given a few users I spoke to believe restricting the edit policy blocks comments, This allows an underpriveleged user to gain access to carry out a restrcited action. (Mongoose)

Report Details

Additional information and metadata

State

Closed

Substate

Informative

Submitted

Weakness

Improper Access Control - Generic