StudentManager icon indicating copy to clipboard operation
StudentManager copied to clipboard

Arbitrary Password Reset Found in teacher/personal.jsp

Open p0l42 opened this issue 2 years ago • 0 comments

I found a arbitrary password reset in teacher/personal.jsp. When a user modify its information, here is not a check about who it is, and call update_teacher, update database columns just according to id user controlled. image When a hacker modify uid to someone's uid, someone's information and password can be resetted as what hacker wants. image image image

p0l42 avatar Dec 24 '23 08:12 p0l42