Read-only administrator can change agent update settings

Disclosed: 2022-08-10 09:38:40 By mega7 To acronis
Medium
Vulnerability Details
Hello Gents, + While testing `eu2-cloud.acronis.com` I found that read-only administrators are able to update agents just by editing the HTML! ### Steps to reproduce: 1. Please login at https://eu2-cloud.acronis.com/mc/ 2. From Users, invite a new user with Read-only administrator role. 3. From Read-only administrator account navigate to "Agents Update" https://eu2-cloud.acronis.com/mc/app;group_id=*******/settings/agents-update 4. Inspect element -> search for `readonly`. 5. Change the value from `readonly="true"` to `readonly="false"`. 6. Edit, update and save. 7. Now open the "Agents Update" page from the company administrator account, you will be able to see the changes! ### Proof of concept: + {F1688988} ## Impact Read-only administrator is able to edit and "Agents Update"
Actions
View on HackerOne
Report Stats
  • Report ID: 1538004
  • State: Closed
  • Substate: resolved
  • Upvotes: 25
Share this report