Description
Accepting permission fields such as Role, IsAdmin, or IsPrivileged from registration or profile-update requests and saving them to an account can let users elevate their own privileges.
Potential impact
- Ordinary users may assign themselves administrator or other privileged roles.
- Bypassed access checks can expose administrative functions, sensitive data, and internal operations.
Remediation
Remove role and permission fields from client request models. Handle role changes in a separate administrative function and verify on the server that the caller may grant the requested role.
Examples
Before
csharp
var user = new User
{
Email = request.Email,
Role = request.Role ?? "User"
};
After
csharp
var user = new User
{
Email = request.Email,
Role = "User"
};
Explanation:
- Before: Assigning role or permission fields from a request to an account can let users grant themselves elevated privileges.
- After: Do not bind roles or permission flags from client input.