Skip to content

Arbitrary password modification vulnerability #99

Closed
@Gitaddy

Description

存在任意用户修改密码漏洞(Arbitrary password modification vulnerability)
官方试用地址:http://try.powerjob.tech/#/welcome
注册账号1:test1 / 123456
注册账号2:test2 / 123456
1
2
进入账号1:
3
修改用户密码:
4
5
不存在身份校验等凭证,直接可以修改用户test2的密码
这里仅存的就是id,但是由于是直接递增的,所以test2的id应该是73
6
最后登录成功:
7
8

Metadata

Assignees

Labels

bugSomething isn't working

Type

No type

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions