account_id was permitted in strong parameters, allowing authenticated admins to transfer resources (Portals, Automation Rules, Macros) to arbitrary accounts. Fix: Removed account_id from permitted params in 4 controllers: - portals_controller.rb - automation_rules_controller.rb - macros_controller.rb - twilio_channels_controller.rb |
||
|---|---|---|
| .. | ||
| accounts | ||
| integrations | ||
| profile | ||
| widget | ||
| accounts_controller.rb | ||
| notification_subscriptions_controller.rb | ||
| profiles_controller.rb | ||
| webhooks_controller.rb | ||