ming-soft / MCMS

完整开源!Java快速开发平台!基于Spring、SpringMVC、Mybatis架构,MStore提供更多好用的插件与模板(文章、商城、微信、论坛、会员、评论、支付、积分、工作流、任务调度等,同时提供上百套免费模板任意选择),价值源自分享!铭飞系统不仅一套简单好用的开源系统、更是一整套优质的开源生态内容体系。铭飞的使命就是降低开发成本提高开发效率,提供全方位的企业级开发解决方案,每月28定期更新版本
http://www.mingsoft.net
MIT License
1.49k stars 662 forks source link

Token reuse vulnerability exists #92

Closed CyberIKUN closed 2 years ago

CyberIKUN commented 2 years ago

Login default account username:msopen password:msopen image Enter the home page image F5 refresh and intercept request packets image Copy the Cookie and click 退出 to log in image Back to the home page image Press F5 again to refresh and intercept the request packet image Add the cookie you just copied image Then put the package and successfully enter the home page image Repair suggestions: After the user logs out, the cookie should be destroyed

killfen commented 2 years ago

5.2.9 fix it