Page MenuHomePhabricator

Badge creation possible without appropriate permission
Closed, ResolvedPublic

Assigned To
Authored By
jxc
Sep 24 2015, 10:22 PM
Referenced Files
F835154: pasted_file
Sep 24 2015, 10:22 PM
F835157: pasted_file
Sep 24 2015, 10:22 PM
Subscribers

Description

Steps to reproduce:

  • Go to badges
  • CMD + left click on Create Badge

pasted_file (40×150 px, 2 KB)

  • Fill out the form
  • Submit
    pasted_file (39×207 px, 3 KB)

Event Timeline

jxc updated the task description. (Show Details)
jxc added a subscriber: jxc.
epriestley triaged this task as Normal priority.
epriestley added a project: Badges.

Thanks for the report! This should be resolved in HEAD and deployed to this server.

I think you earned the badge.

(We maintain a vulnerability program with HackerOne, but this specific issue is pretty fluff and in a prototype application so I don't think it meets the minimum bar for a vulnerability award ("significantly compromise ... typical installation"). Feel free to file through HackerOne if you hit anything security-esque and more substantive in the future, though.)