Skip to content

Commit 60c8211

Browse files
authored
Update IDOR2.java
admin.无法登录 另外建议让zhangwei和admin都可以登录系统,不要写死只有admin登录 这样就可以很好的对比zhangwei不能访问这个safe/admin的url,对比越权漏洞
1 parent 063ca3b commit 60c8211

File tree

1 file changed

+1
-1
lines changed
  • src/main/java/com/best/hello/controller/IDOR

1 file changed

+1
-1
lines changed

src/main/java/com/best/hello/controller/IDOR/IDOR2.java

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -23,7 +23,7 @@ public String vul() {
2323
// 只允许admin用户可以访问管理页面
2424
@GetMapping(value = "/safe/admin")
2525
public String safe(HttpSession session) {
26-
if (session.getAttribute("LoginUser").equals("admin.")) {
26+
if (session.getAttribute("LoginUser").equals("admin")) {
2727
return "idoradmin";
2828
} else {
2929
return "commons/403";

0 commit comments

Comments
 (0)