Configuration

Securing Inbound actions


Security
A01: Broken Access Control
0h 30m to fix

Why is this an issue?

Only users with the required roles should be allowed to trigger inbound action.

Best practices

All inbound actions (table Inbound Email Actions sysevent_in_email_action) should have roles mentioned in "Required roles" field to secure actions triggered from inbound actions.

Disable Embedded HTML Code property
Disable SQL error messages

© Copyright 2025. All rights reserved.