-
Notifications
You must be signed in to change notification settings - Fork 17
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Unauthorized Access fro Modification of User Details via Account Number #2
Comments
Can i be assigned this one?? |
!assign @MKD2004 |
Can I be assigned to this issue? |
!assign @Rxnnie-08 |
@Rxnnie-08 default time is 30mins show me the progress and i will extend the time (show me before the time runs out) |
Can I pls be assigned? |
Hey @Lohithsurya! The timer for the @Rxnnie-08 to work on the issue has finished, deassign and assign a new contributor or extend the current timer. Contact maintainer leads if inactive @DedLad @polarhive @achyuthcodes30 |
can i get assigned |
1 similar comment
can i get assigned |
can i get assigned this |
!deassign |
1 similar comment
!deassign |
Can I get assigned to this issue? @Lohithsurya |
can i get it assigned? |
can I please get this assigned |
can I please get this assigned? |
can I get this assigned? |
can i get this assigned? |
@Lohithsurya can you assign this to me? |
!assign @Anyaaa-2 |
can i be assigned please? |
Hey @Lohithsurya! The timer for the @Anyaaa-2 to work on the issue has finished, deassign and assign a new contributor or extend the current timer. Contact maintainer leads if inactive @DedLad @polarhive @achyuthcodes30 |
can you extend it and give me more time |
could u assign this |
could u assign this |
If a user knows the account number, they are able to change the personal details of the account holder without any further authentication or authorization. This poses a security risk as anyone with the account number can modify sensitive information.
Expected Behavior:
Modifying account details should require proper authentication, such as a password .
Simply knowing the account number should not allow changes to personal information.
The text was updated successfully, but these errors were encountered: