EIQ-2021-0001
ID |
EIQ-2021-0001 |
CVE |
- |
Description |
Platform users can edit work-in-progress (draft) forms by ID |
Date |
14 Jan 2021 |
Severity |
2 - MEDIUM |
CVSSv3 score |
CVSSv3 score not available on NIST NVD. |
Status |
2.9.1 |
Assessment |
The platform stores intermediate changes as work-in-progress drafts. This enables users to suspend working, and then to resume it later, without losing their progress. Signed-in platform users can edit work-in-progress (draft) forms created by other users. For example, they can change other users' account details by specifying a different email address to receive automated notifications from the platform; or they can edit the user name. To do so, a potential attacker would need to send a request to the /private/work-in-progress API endpoint. The endpoint supports the following HTTP methods:
To exploit the vulnerability, a potential attacker would need:
|
Mitigation |
To mitigate this vulnerability:
|
Affected versions |
2.9.0 and earlier. |
Notes |
For more information, see: This section is not visible to users accessing the public docs, it's for internal reference See also:
|
< Back to all security issues and mitigation actions
In release notes 2.9.1