Openbravo Issue Tracking System - Openbravo ERP
View Issue Details
0034491Openbravo ERPA. Platformpublic2016-11-14 13:242022-02-01 08:05
caristu 
Triage Platform Base 
highminoralways
acknowledgedopen 
5
 
 
AugustoMauch
Core
No
0034491: Review access for DeleteImageActionHandler class
It is possible to delete images different from the last recently added if they are accessible by the client and organization of the login context.
In description
The DeleteImageActionHandler should not delete any image but the ones created and dropped during record creation (see issue 0026253)
security
related to defect 00262533.0PR14Q3 closed guillermogil Trash button in product window, image field is not removing the image from database 
related to defect 0041748 closed cberner DeleteImageActionHandler is vulnerable to CSRF attacks 
Issue History
2016-11-14 13:24caristuNew Issue
2016-11-14 13:24caristuAssigned To => platform
2016-11-14 13:24caristuModules => Core
2016-11-14 13:24caristuTriggers an Emergency Pack => No
2016-11-14 13:24caristuRelationship addedrelated to 0034490
2016-11-14 13:30caristuSteps to Reproduce Updatedbug_revision_view_page.php?rev_id=13681#r13681
2016-11-14 13:30caristuProposed Solution updated
2016-11-14 13:30caristuRelationship addedrelated to 0026253
2016-11-14 13:30caristuProposed Solution updated
2016-11-14 13:31caristuDescription Updatedbug_revision_view_page.php?rev_id=13683#r13683
2016-11-14 13:31caristuFile Added: curlDeleteImage.txt
2016-11-14 13:47caristuSteps to Reproduce Updatedbug_revision_view_page.php?rev_id=13687#r13687
2016-11-14 17:50caristuSummary[clustering] DeleteImageActionHandler is unsecure => [clustering] Review access for DeleteImageActionHandler class
2016-11-14 17:50caristuDescription Updatedbug_revision_view_page.php?rev_id=13701#r13701
2016-11-14 17:50caristuSteps to Reproduce Updatedbug_revision_view_page.php?rev_id=13702#r13702
2016-11-14 17:58caristuFile Deleted: curlDeleteImage.txt
2016-11-15 11:14caristuSummary[clustering] Review access for DeleteImageActionHandler class => Review access for DeleteImageActionHandler class
2016-11-16 16:39alostaleRelationship deletedrelated to 0034490
2016-12-01 12:18alostaleStatusnew => acknowledged
2016-12-01 14:03alostalePrioritynormal => high
2016-12-16 14:45caristuTag Attached: security
2019-08-23 13:55cbernerAssigned Toplatform => cberner
2019-08-27 09:28cbernerStatusacknowledged => scheduled
2019-08-27 09:28cbernerReview Assigned To => AugustoMauch
2019-08-28 08:09cbernerStatusscheduled => acknowledged
2019-09-04 12:43cbernerRelationship addedrelated to 0041748
2019-12-26 11:48cbernerAssigned Tocberner => platform
2022-02-01 08:05alostaleAssigned Toplatform => Triage Platform Base

There are no notes attached to this issue.