3.4K Star 20.6K Fork 6.9K

GVP微同软件 / 微同商城

 / 详情

[security vulnerability] Arbitrary Order goods Access

待办的
创建于  
2023-12-20 14:09

Recently, our team found an Arbitrary Order goods Access vulnerability in the latest version of the project.

The vulnerability logic is present in the file:https://gitee.com/fuyang_lipengjun/platform/blob/master/platform-api/src/main/java/com/platform/api/ApiOrderController.java#95.

输入图片说明

The operation com.platform.dao.ApiOrderGoodsMapper.queryList() is not protected by permission checks,
while the request of path 'detail' is also unauthorized, which means an attacker can achieve Arbitrary Order goods Access.

To address this vulnerability, we strongly advise that developers implement access control policies that limit API access to admin users or the owner.

评论 (0)

GatekeeperBuster 创建了任务

登录 后才可以发表评论

状态
负责人
里程碑
Pull Requests
关联的 Pull Requests 被合并后可能会关闭此 issue
分支
开始日期   -   截止日期
-
置顶选项
优先级
参与者(1)
Java
1
https://gitee.com/fuyang_lipengjun/platform.git
git@gitee.com:fuyang_lipengjun/platform.git
fuyang_lipengjun
platform
微同商城

搜索帮助