Closed
Description
Preconditions (*)
- Magento 2.4.3
Steps to reproduce (*)
-
Modify value of Conditions option value in browser's inspect. For example:
-
Select the option that you have modified.
Expected result (*)
- Validation error
Actual result (*)
- Inserted class is created and Magento tries to call methods on it. Have not found an actual exploit but this seems to be really bad practice at best.
Please provide Severity assessment for the Issue as Reporter. This information will help during Confirmation and Issue triage processes.
- Severity: S0 - Affects critical data or functionality and leaves users without workaround.
- Severity: S1 - Affects critical data or functionality and forces users to employ a workaround.
- Severity: S2 - Affects non-critical data or functionality and forces users to employ a workaround.
- Severity: S3 - Affects non-critical data or functionality and does not force users to employ a workaround.
- Severity: S4 - Affects aesthetics, professional look and feel, “quality” or “usability”.