We read every piece of feedback, and take your input very seriously.
To see all available qualifiers, see our documentation.
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
最近有人刷本校评课网站的忘记密码的邮件发送接口,才注意到这个问题:
reg_verify
ustc-course/app/views/api.py
Lines 255 to 264 in 5556d25
可能的解决方案:提交注册或忘记密码表单前加验证码 ( SUSTech-CRA@021e06a ) 或表单验证 ( SUSTech-CRA@05001e9 )
The text was updated successfully, but these errors were encountered:
No branches or pull requests
最近有人刷本校评课网站的忘记密码的邮件发送接口,才注意到这个问题:
reg_verify
这个api检查邮箱和用户名有没有被注册过,但这个api没有做限制Origin或者限制session的措施,在邮件规则已知的情况下(比如邮箱前缀都是数字的学生邮箱)可能会被人快速穷举ustc-course/app/views/api.py
Lines 255 to 264 in 5556d25
可能的解决方案:提交注册或忘记密码表单前加验证码 ( SUSTech-CRA@021e06a ) 或表单验证 ( SUSTech-CRA@05001e9 )
The text was updated successfully, but these errors were encountered: