Lucene search

K
huntrLekhang123lc89D996A2-DE30-4261-8E3F-98E54CB25F76
HistoryApr 13, 2022 - 2:55 a.m.

Improper access control could make any user export all user of website

2022-04-1302:55:13
lekhang123lc
www.huntr.dev
17
access control
user data
website

EPSS

0.001

Percentile

49.6%

Description

A user who has to change their password after logging in can export the website’s user data.

Proof of Concept

Step 1: login to website by admin account and change password of a user. Check the box “Force password change upon next login” and save.

Step 2: login to website by the account you just change the password. You will see a change password page.

Step 3: go to the link: domain/admin/user/export?format=xlsx. You will see this account can export the data of users without admin privilege.

You may try it out on ncsctest.humhub.com, which is my demo site. After logging in, a user tester / 123123 will be forced to change their password. You can view the export file humhub user.xlsx at https://ncsctest.humhub.com/admin/user/export?format=xlsx.

EPSS

0.001

Percentile

49.6%

Related for 89D996A2-DE30-4261-8E3F-98E54CB25F76