Read-only administrator can change agent update settings
Medium
Vulnerability Details
Hello Gents,
+ While testing `eu2-cloud.acronis.com` I found that read-only administrators are able to update agents just by editing the HTML!
### Steps to reproduce:
1. Please login at https://eu2-cloud.acronis.com/mc/
2. From Users, invite a new user with Read-only administrator role.
3. From Read-only administrator account navigate to "Agents Update" https://eu2-cloud.acronis.com/mc/app;group_id=*******/settings/agents-update
4. Inspect element -> search for `readonly`.
5. Change the value from `readonly="true"` to `readonly="false"`.
6. Edit, update and save.
7. Now open the "Agents Update" page from the company administrator account, you will be able to see the changes!
### Proof of concept:
+ {F1688988}
## Impact
Read-only administrator is able to edit and "Agents Update"
Actions
View on HackerOneReport Stats
- Report ID: 1538004
- State: Closed
- Substate: resolved
- Upvotes: 25