diff --git a/src/main/java/com/best/hello/controller/IDOR/IDOR2.java b/src/main/java/com/best/hello/controller/IDOR/IDOR2.java index cf8d5af..3b2576a 100644 --- a/src/main/java/com/best/hello/controller/IDOR/IDOR2.java +++ b/src/main/java/com/best/hello/controller/IDOR/IDOR2.java @@ -23,7 +23,7 @@ public String vul() { // 只允许admin用户可以访问管理页面 @GetMapping(value = "/safe/admin") public String safe(HttpSession session) { - if (session.getAttribute("LoginUser").equals("admin.")) { + if (session.getAttribute("LoginUser").equals("admin")) { return "idoradmin"; } else { return "commons/403";