Permissive parameters and privilege escalation
Moderate severity
GitHub Reviewed
Published
Feb 10, 2022
to the GitHub Advisory Database
•
Updated Jan 11, 2023
Description
Reviewed
Jan 27, 2022
Published to the GitHub Advisory Database
Feb 10, 2022
Last updated
Jan 11, 2023
An issue was discovered in Steve Pallen Coherence before 0.5.2 that is similar to a Mass Assignment vulnerability. In particular, "registration" endpoints (e.g., creating, editing, updating) allow users to update any coherence_fields data. For example, users can automatically confirm their accounts by sending the confirmed_at parameter with their registration request.
References