Project

General

Custom queries



Profile

Actions

Defect #37171

closed

Ability to change the issue category or issue target version with nonexistent value for the specific project

Added by Nikola Milanov almost 3 years ago. Updated almost 3 years ago.

Status:
Closed
Priority:
High
Category:
Security
Target version:
Start date:
Due date:
% Done:

0%

Estimated time:
Resolution:
Fixed
Affected version:

Description

Hi there,
I found a way to change category with nonexistent ID for the specific project.
I will try to explain it in more details (the user making the change has access to the project)
1. User start editing the ticket (click "Edit" button)
2. Right click on Category field and choose "Inspect" (Developer's tool)
3. Then we change the value of the category to one that is not in the project
4. Click "Submit" button and we save the ID of category that not exist for the specific folder.

Is there any way to make to verify that this category is in the project to avoid this kind of changes?

Cheers


Files

#1

Updated by Mischa The Evil almost 3 years ago

  • Subject changed from Ability to change the category with nonexistent for the specific project to Ability to change the issue category with nonexistent value for the specific project
  • Category changed from Issues to Security
  • Status changed from New to Confirmed
  • Priority changed from Normal to High
  • Private changed from No to Yes
#2

Updated by Holger Just almost 3 years ago

  • Assignee set to Holger Just
#3

Updated by Holger Just almost 3 years ago

#4

Updated by Marius BĂLTEANU almost 3 years ago

  • Status changed from Confirmed to Resolved
  • Target version set to 4.2.7
  • Resolution set to Fixed
#5

Updated by Marius BĂLTEANU almost 3 years ago

  • Subject changed from Ability to change the issue category with nonexistent value for the specific project to Ability to change the issue category or issue target version with nonexistent value for the specific project
  • Status changed from Resolved to Closed
#6

Updated by Marius BĂLTEANU almost 3 years ago

  • Private changed from Yes to No
Actions

Also available in: Atom PDF