Skip to content

Dev/sec2/v5.spirngboot5#39

Open
aibot88 wants to merge 2 commits into
thinkgem:v5.springboot3from
aibot88:dev/sec2/v5.spirngboot5
Open

Dev/sec2/v5.spirngboot5#39
aibot88 wants to merge 2 commits into
thinkgem:v5.springboot3from
aibot88:dev/sec2/v5.spirngboot5

Conversation

@aibot88
Copy link
Copy Markdown

@aibot88 aibot88 commented May 25, 2026

This patch is to fix all vulns reported by aibot88, the detailed is following:

interface overview

${adminPath}/sys/empUser/save
${adminPath}/sys/empUser/importData
${adminPath}/sys/post/save

root case analysis

Missing Check for - empUser.employee.office.officeCode

  • empUser.employee.company.companyCode
  • empUser.employee.employeePostList[].postCode
  • empUser.employee.employeeOfficeList[].officeCode
  • empUser.employee.employeeOfficeList[].postCode- importedEmpUser.employee.office.officeCode
  • importedEmpUser.employee.company.companyCodepost.roleCodes

For ethic concern, more detailed PoC and threats info please contact me in wechat (we are already friends)

@think-gem
Copy link
Copy Markdown
Member

同类型 pr:#38

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants