Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Deleted User can still operate successfully #241

Open
menghaining opened this issue May 29, 2024 · 0 comments
Open

Deleted User can still operate successfully #241

menghaining opened this issue May 29, 2024 · 0 comments

Comments

@menghaining
Copy link

Description

The deleted user can still operate, suffering from CWE-613.

Affected version

v4.7.8 and before

POC

  1. admin login, user1 login
    image

  2. admin delete user1
    image

image

  1. user1 can still change his/her information and even reset his/her password successfully.
    image

image

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant