Skip to content

UmsMemberController.java:getMemberPage可能存在权限漏洞 #122

@old6ma

Description

@old6ma

这里需要对会员身份进行认证才能返回会员页面,这里代码本身是通过昵称来模糊匹配并返回所有与该昵称类似的会员,需要对会员身份进行检查(比如是否为管理员还是普通用户,普通用户应该不能随便访问会员相关信息)
@Operation(summary= "会员分页列表") @GetMapping public PageResult<UmsMember> getMemberPage( @Parameter(name = "页码") Long pageNum, @Parameter(name = "每页数量") Long pageSize, @Parameter(name = "会员昵称") String nickName ) { IPage<UmsMember> result = memberService.list(new Page<>(pageNum, pageSize), nickName); return PageResult.success(result); }

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type
    No fields configured for issues without a type.

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions