[HackerOne] A user can still edit his/her answer after it has been accepted leading to loss of integrity
Categories
(support.mozilla.org :: General, enhancement)
Tracking
(Not tracked)
People
(Reporter: frida, Unassigned)
Details
Link: https://hackerone.com/reports/2089307
Date: 2023-07-29 10:56:05 UTC
By: tomorrowisnew_
Weakness: Business Logic Errors
Details:
Summary:
After the author of the question picked the right answer. That answer will be shown for other people having the same question. The website shouldn't allow a user to edit his/her answer after having it accepted, because this might lead to misinformation
Steps To Reproduce:
- Have 2 accounts, in support.allizom.org. We will call these 2 users as user a and user b respectively
- As user a, create a question, in https://support.allizom.org/en-US/questions/new/desktop/form
- As user b, make an answer
- As user a, mark user b's answer as the solution
- Now user b's answer is shown as the right answer when visiting the question
- As user b, edit your answer. See that you still can and it will reflect the answer shown when viewing the question
Impact
Summary:
With this, a user can spread misinformation, by providing wrong answers to new users
| Reporter | ||
Updated•2 years ago
|
| Reporter | ||
Comment 1•2 years ago
|
||
Hello Tasos,
Can you please take a look? I don't think this a security issue and I closed it as informative on HackerOne. I am curious whether it would be possible to lock the answer once it's chosen as the accepted answer.
Thanks,
Frida
Comment 2•2 years ago
|
||
Hi Frida,
I would agree that it's not a security bug. I will keep this bug open and have a conversation with the stakeholders about the functionality of the site and whether we want to lock the editing of a question after it's marked as the solution.
Comment 3•2 years ago
|
||
Frida, could you remove the security flag? I don't have the permission to do so
| Reporter | ||
Updated•2 years ago
|
| Reporter | ||
Comment 4•2 years ago
|
||
Done. Please let me know if you need anything else.
Description
•