Absolute path disclosure/Path traversal is possible:

Absolute path disclosure/Path traversal is possible:

by suraj kumar -
Number of replies: 1


Application displays the absolute path for all the function/objects which may be misused for getting

the access of even those functions which needs to be protected by application flow & access to be

allowed only to authenticated & authorized users which are supposed to access these. Parameter

Manipulation is also possible. For example -when profile of teacher user is clicked it displayed id=29

in its url, when we manipulated it to 30 and another users’ profile page got opened.


please help

Average of ratings: -
In reply to suraj kumar

Re: Absolute path disclosure/Path traversal is possible:

by Marcus Green -
Picture of Core developers Picture of Particularly helpful Moodlers Picture of Plugin developers Picture of Testers

Was the system set so that profile should not have been displayed it the link for it had been clicked?