Incorrect Authorization in User role in limesurvey/limesurvey
Reported on
Sep 27th 2023
Description
Incorrect Authorization in User role
Proof of Concept
1 .Default, administrator (User ID =1 ) cannot add user roles
2 .Remove the "disable" class at Inspect
3 .After that, add the user role success
Video Poc
https://drive.google.com/file/d/1vQPHZwaghByHsqEgQI9p3EiGeVCTbLK7/view?usp=sharing
Impact
Add arbitrary user roles, do not authenticate users, affect permissions
@tiborpacalat, I'm sorry for the inconvenience. Maybe I misunderstood CSRF. I have revised the report. Please check the report again. Thank very much.