-
Notifications
You must be signed in to change notification settings - Fork 775
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
hustoj IDOR Vulunerability #1065
Comments
thank you for reporting! |
If it turns out to be a valid vulnerability, can I get a CVE id? |
I don't know how to give you one. |
But there's a case CVE-2022-42187 |
sorry for unfamiliar with the rules of sec, still don't know what ToDo to confirm your contibution. |
I don't use php very well. I just saw the possibility of a vulnerability and reported it, but if it's not valid, you can ignore it. Sorry again for not being helpful.... |
You are helping , the latest code is patched, just tell the administrator of the site you are using to update "thread.php" |
If you can help us translate the new added English words into Korean , that will be even helpful. |
Oh, was it a patched vulnerability? sry |
描述问题
IDOR Vulunerability (Improper Data Deletion) in
/thread.php?tid={TID}
如何复现
Users can access deleted posts by manipulating the tid value
For example, even if a thread corresponding to tid 1 is created and deleted, it is still accessible by manipulating url query
/thread.php?tid=1
Expected behavior
The deleted thread should not be accessible
Screenshots
SERVER OPTION
CSL HUSTOJ (release 24.01.30)
Modified by CSL 2025
GPLv2 licensed by HUSTOJ 2025
target: every device
The text was updated successfully, but these errors were encountered: