Skip to content

发现一个重大漏洞 #6

@929408183

Description

@929408183

可以通过 //admin路径开头跳过登录拦截器,访问后台接口,接口能够正常访问。
例如:
post http://127.0.0.1//admin/v1/blogConfig/add
参数
configField=111
configName=111
configValue=111
无需登录即可访问接口
image

Metadata

Metadata

Assignees

Labels

bugSomething isn't working

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions