logo

Database

Description

For an authenticated user with a profile that restricts certain functions, the restriction is performed on the front end by disabling the corresponding button, which can be bypassed and the query is processed when it is sent.

Impact

Access customer information on a massive scale.

Recommendation

Verify on the server side that the user making the request has sufficient permissions.

Threat

Authenticated user from the Internet.

Expected Remediation Time

⏱️ 30 minutes.