Project

General

Profile

Actions

Bug #7887

closed

User permissions do not protect firewall rules

Added by Michael Newton over 6 years ago. Updated over 6 years ago.

Status:
Not a Bug
Priority:
Normal
Assignee:
-
Category:
Web Interface
Target version:
-
Start date:
09/21/2017
Due date:
% Done:

0%

Estimated time:
Plus Target Version:
Release Notes:
Affected Version:
2.3.4_1
Affected Architecture:

Description

User permissions have only cosmetic effect on the firewall page, if any, and are trivially easy to bypass.

Steps to reproduce:
1. Create a user
2. Assign "WebCfg - Firewall: Rules" privilege
3. DO NOT assign "WebCfg - Firewall: Rules: Edit" privilege
4. Log in as new user, view firewall rules
5. Disable some rules, move some around
6. Right click on Save button, inspect in browser's tools and remove "disabled" attribute
7. Click Save and apply changes
8. You are an elite hacker

The failure to check for editing permissions here is kind of a big oversight.

Actions

Also available in: Atom PDF