权限设置不当
SourceCodester 人力资源管理系统 1.0 中的 /hrm/controller/ccity.php?positionedit= 存在权限设置不当漏洞,攻击者可访问普通用户无权访问的功能。
路径 URL:/hrm/controller/ccity.php?positionedit=
参数:position.php
攻击者可使用普通账户添加新职位,而普通用户本无权执行此操作。
https://github.com/dovankha/CVE-2024-34221/assets/63991630/667ddbd4-af03-4959-9f20-765e9e8a8bae