Skip to content

There are two vulnerabilities of missing authorization #6

@ixpqxi

Description

@ixpqxi

1 Vulnerability basic information

  • Name of software: Lost-And-Found
  • Software Download: https://github.com/AvinashAnand02/Lost-And-Found
  • Affected version: main
  • Types of vulnerabilities: Missing Authorization (CWE-862)
  • Vulnerability description and hazards: In Lost-And-Found, when participants attempt to access resources or perform operations, authorization checks are not conducted. This leads to unauthorized attackers being able to perform sensitive operations.
  • Vulnerability contributor: Qin Mai of VARAS@IIE

2 Vulnerability recurrence

You can directly send the following data packets to perform the corresponding sensitive operations without identity authentication.

2.1 classes/SystemSettings.php

Image

2.2 classes/Master.php

Image

Metadata

Metadata

Assignees

Labels

No labels
No labels

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions