User Expense Bank Account Details Security Issue
Summary
User Expense Bank Account Details Security IssueContent
Hi Community,
We have recently come across a issue we have great concern over where a user is able to create a bank account under his user that already exists for another users in the system.
Example steps to replicate the issue:
1. Adam has entered in his bank account details in Expenses (Manage bank Account)
2. Jill then enters in the exact same bank account in Expenses (Manage bank Account). A warning is shown but allows the user to save and share the account with Adam.
3. After Jill adds the same account as Adam, Jill can then make changes to that bank account which are reflected on Adam's Account as they both share the account
Tagged:
0