We read every piece of feedback, and take your input very seriously.
To see all available qualifiers, see our documentation.
Have a question about this project? # for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “#”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? # to your account
最近有人刷本校评课网站的忘记密码的邮件发送接口,才注意到这个问题:
reg_verify
ustc-course/app/views/api.py
Lines 255 to 264 in 5556d25
可能的解决方案:提交注册或忘记密码表单前加验证码 ( SUSTech-CRA@021e06a ) 或表单验证 ( SUSTech-CRA@05001e9 )
The text was updated successfully, but these errors were encountered:
No branches or pull requests
最近有人刷本校评课网站的忘记密码的邮件发送接口,才注意到这个问题:
reg_verify
这个api检查邮箱和用户名有没有被注册过,但这个api没有做限制Origin或者限制session的措施,在邮件规则已知的情况下(比如邮箱前缀都是数字的学生邮箱)可能会被人快速穷举ustc-course/app/views/api.py
Lines 255 to 264 in 5556d25
可能的解决方案:提交注册或忘记密码表单前加验证码 ( SUSTech-CRA@021e06a ) 或表单验证 ( SUSTech-CRA@05001e9 )
The text was updated successfully, but these errors were encountered: