T05 · Unauthorized Access and Privilege Escalation
- Location
scripts/tier_config.py:48- Finding
Paid Feature Authorization Can Be Forged Using Arbitrary Token Prefixes or Caller-Controlled Overrides
- Content
View full analysis
str: """Detect tier from token prefix or plan_id.""" if not self.token: return "FREE" token_upper = self.token.upper() for tier_name, prefix in TOKEN_PREFIXES.items(): if token_upper.startswith(prefix): return tier_name return "FREE" ``` The explicit token validation is also limited to a prefix comparison: ```python def validate_token(self, token: str) -> bool: """Validate that token matches expected prefix for tier.""" if not token: return True # No token = Free tier token_upper = token.upper() expected_prefix = TOKEN_PREFIXES.get(self.tier_name, "") if not expected_prefix: return True return token_upper.startswith(expected_prefix) ``` The resulting caller-controlled entitlement is trusted when paid functionality is enabled: ```python # Export Excel if tier supports excel_path = None if tier.can_export_excel() and (result["matched"] or result["differences"] or result["unclaimed"] or result["unmatched_orders"]): exporter = ReconciliationExporter() excel_path = exporter.export(result) result["excel_path"] = excel_path ``` ### Technical Analysis The subscription token is not authenticated, cryptographically verified, or checked against a trusted subscription service. A token is accepted solely because its text starts with a known string such as `BANK-PRO` or `BANK-ENT`. Additionally, the constructor accepts `tier_name` and `is_pro` directly from the caller. These values override or supplement token-derive ...[truncated 1890 chars]- Remediation
View remediation
