StudentManager icon indicating copy to clipboard operation
StudentManager copied to clipboard

Arbitrary Password Reset Found in student/personal.jsp

Open p0l42 opened this issue 2 years ago • 0 comments

I found a arbitrary password reset in student/personal.jsp. When a user modify its information, here is not a check about who it is, and calls update_student_security, updates database columns just according to id user controlled. image When a hacker modify uid to someone's uid, someone's information and password can be resetted as what hacker wants. Following images are the information not modified, and I login as 20162430635. image image I modify the id to 20162430636, and send the package, user-36's information is modified. image image

p0l42 avatar Dec 24 '23 09:12 p0l42