Skip to content

Security Vulnerability: Lack of Authorization Mechanism #228

@Somesh-nayek

Description

@Somesh-nayek

The routes are not checking whether the person who wants to add or delete information from an account is authorised to do that or not.
If the check is not implemented ,anyone can delete anyone's data and that will be a security breach.

Screenshot 2024-10-07 122656
Screenshot 2024-10-07 122704

In the example snippet above there is not authorization check.
@Sahil1786 ,I want to work on this .please assign me this under GSSOC-2024

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions