Insecure functionality - File Creation
Description
For an authenticated user with a profile that restricts certain functions, the restriction is performed on the front end by disabling the corresponding button, which can be bypassed and the query is processed when it is sent.
Impact
Access customer information on a massive scale.
Recommendation
Verify on the server side that the user making the request has sufficient permissions.
Threat
Authenticated user from the Internet.
Expected Remediation Time
⏱️ 30 minutes.
Requirements
266 - Disable insecure functionalities