Project

General

Profile

Actions

Bug #9692

closed

system_authservers.php: Descriptive name can be changed by removing read-only property via inspect element

Added by Alex Z over 5 years ago. Updated almost 5 years ago.

Status:
Resolved
Priority:
Very Low
Assignee:
Category:
User Manager / Privileges
Target version:
Start date:
08/21/2019
Due date:
% Done:

100%

Estimated time:
Plus Target Version:
Release Notes:
Affected Version:
2.4.4-p3
Affected Architecture:

Description

Steps to reproduce:

  • Go to System -> User Mgmt -> Authentication Servers
  • Edit an existing entry
  • Open source code of the webpage in the browser's dev-tools and manipulate the value of the first field "Descriptive name"
  • Click save

Expected behavior:
Descriptive name should not change

Current behavior:
Descriptive name is changed to whatever was entered in the source code view

Actions

Also available in: Atom PDF