Skip to content

Conversation

@fn20200323
Copy link
Contributor

Enumerate reports that can expose data without authentication

@phifogg
Copy link
Collaborator

phifogg commented Oct 29, 2021

Can you elaborate why you chose a script check for this one? Would a table check not be working?

@fn20200323
Copy link
Contributor Author

Can you elaborate why you chose a script check for this one? Would a table check not be working?

Yes, not sure why but table check doesn't work for this table :(
Have tried multiple approach with table check - unfortunatley without success

@fn20200323
Copy link
Contributor Author

Table Check is not able to list records with simple condition (table: sys_report, condition: roles=public)

To achieve the goal decided to do the same using Script Only Check - then it works and return findings.

@phifogg phifogg merged commit 9026ab1 into ServiceNowDevProgram:master Nov 3, 2021
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants