IceCMS icon indicating copy to clipboard operation
IceCMS copied to clipboard

Vulnerabilities that allow arbitrary information traversal and modification by any user

Open Ungitshell opened this issue 1 year ago • 2 comments

api:/api/User/ChangeUser/(self_token) Calling this interface, we can modify the information of any user by modifying the UserID field.there will be no validation image Try to log in to user test39, it goes well image It is obvious that developers only modify user information through UserID without any judgment and filtering image image

Ungitshell avatar Jun 08 '23 09:06 Ungitshell

The address of the reproducible vulnerability:www.macwk.cc 预览地址1 预览地址2

Ungitshell avatar Jun 08 '23 09:06 Ungitshell

it is Inenegligence in authorization.should be apply shiro to certify user.

Thecosy avatar Jun 12 '23 10:06 Thecosy