Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

admin security holes #1343

Open
10 tasks
black3r opened this issue Aug 30, 2020 · 0 comments
Open
10 tasks

admin security holes #1343

black3r opened this issue Aug 30, 2020 · 0 comments

Comments

@black3r
Copy link
Member

black3r commented Aug 30, 2020

veduci (is_staff, group: trojsten) maju stale vela permissionov ktore im umoznuju robit kadejaku sarapatu..., zacnime s potencialnymi security issues (i.e. moznosti obist bezpecnost tam, kde o nejaku snaha bola) podla vaznosti:

  • zmenit email nahodnemu cloveku (co umoznuje zavolat reset password aj pre superadminov)
  • vytvorit duplicitneho pouzivatela pre superadmina a pouzit merge users feature aby sa stali superadminom
  • zmenit skupinu veducich v sutazi ktoru neveducuju a tym padom sa stat veducim nejakej inej sutaze a rozbit to pre realnych veducich danej sutaze
  • mozu zmenit skupinu veducich pre typ sustredenia a tym padom editovat cudzie sustredenia
  • nemozu menit ulohy ani kategorie cudzich sutazi, ale casti ano, teda mozu zmenit sutaz v casti na tu, ktoru vedia ovladat...
  • vidiet (mozno aj editovat) vsetky wiki clanky
  • vidiet (mozno aj editovat) vsetky obrazky a prilohy zo vsetkych wiki clankov

a pridajme niektore dalsie veci, kde zatial ziadna snaha o separaciu stranok nebola a podla mna by sa aj zisla

  • menit novinky a tipy na vsetkych strankach (toto je mozno feature, ale aj tak by som povedal ze by stacilo keby takuto permission malo zopar ludi za seminar (hlavny veduci / povereny webmaster / whatever)
  • editovat vysledkovky vsetkych sutazi
  • vidiet a editovat komentare na vsetkych strankach

toz to su take ktore som narychlo objavil tak ze som si skusil preklikat admina za testovacieho usera ktory je iba v skupine trojsten.., ak viete o nejakych dalsich, pls pridajte...

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

No branches or pull requests

1 participant