Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

hustoj IDOR Vulunerability #1065

Open
logag1 opened this issue Jan 19, 2025 · 10 comments
Open

hustoj IDOR Vulunerability #1065

logag1 opened this issue Jan 19, 2025 · 10 comments

Comments

@logag1
Copy link

logag1 commented Jan 19, 2025

描述问题
IDOR Vulunerability (Improper Data Deletion) in /thread.php?tid={TID}

如何复现
Users can access deleted posts by manipulating the tid value
For example, even if a thread corresponding to tid 1 is created and deleted, it is still accessible by manipulating url query
/thread.php?tid=1

Expected behavior
The deleted thread should not be accessible

Screenshots

Image

Image

SERVER OPTION
CSL HUSTOJ (release 24.01.30)
Modified by CSL 2025
GPLv2 licensed by HUSTOJ 2025

target: every device

@zhblue
Copy link
Owner

zhblue commented Jan 19, 2025

thank you for reporting!
try update thread.php to lateast.

@logag1
Copy link
Author

logag1 commented Jan 20, 2025

If it turns out to be a valid vulnerability, can I get a CVE id?

@zhblue
Copy link
Owner

zhblue commented Jan 20, 2025

I don't know how to give you one.

@logag1
Copy link
Author

logag1 commented Jan 20, 2025

But there's a case CVE-2022-42187

@zhblue
Copy link
Owner

zhblue commented Jan 20, 2025

sorry for unfamiliar with the rules of sec, still don't know what ToDo to confirm your contibution.
maybe you can give us a patch pull request , and I will merge it ?

@logag1
Copy link
Author

logag1 commented Jan 20, 2025

I don't use php very well. I just saw the possibility of a vulnerability and reported it, but if it's not valid, you can ignore it. Sorry again for not being helpful....

@zhblue
Copy link
Owner

zhblue commented Jan 20, 2025

You are helping , the latest code is patched, just tell the administrator of the site you are using to update "thread.php"

@zhblue
Copy link
Owner

zhblue commented Jan 20, 2025

If you can help us translate the new added English words into Korean , that will be even helpful.
https://github.com/zhblue/hustoj/blob/master/trunk/web/lang/ko.php

@logag1
Copy link
Author

logag1 commented Jan 20, 2025

Oh, was it a patched vulnerability? sry
If you tell me how to translate Korean, I will help you

@zhblue
Copy link
Owner

zhblue commented Jan 20, 2025

first , fork this project
second, edit it in your fork, just replace the English value in quotes with Korean.
Image

after save all the changes, create a pull request.

Image

just browse the homepage of your fork, github might show a big green button for you to do it .

Image

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants