We read every piece of feedback, and take your input very seriously.
To see all available qualifiers, see our documentation.
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
很多敏感操作没有权限检查 举例子,在未登录的情况下访问如下地址 zsj.itdos.net/admin/user/ 可以获取所有账号的信息,包括密码的MD5值,通过在线的md5解密服务即可获取密码
The text was updated successfully, but these errors were encountered:
谢谢提醒。安全这块确实前期重视不够,主要精力都在功能上了。我将对接口进行检查,加权限。
Sorry, something went wrong.
已经修复user接口
No branches or pull requests
很多敏感操作没有权限检查

举例子,在未登录的情况下访问如下地址
zsj.itdos.net/admin/user/
可以获取所有账号的信息,包括密码的MD5值,通过在线的md5解密服务即可获取密码
The text was updated successfully, but these errors were encountered: