<aside> ๐Ÿ“Ž Content

Admin Registration


Improper Input Validation Register as a user with administrator privileges.

Untitled

Untitled

ํšŒ์› ๊ฐ€์ž… ์š”์ฒญ ์‹œ ์ „๋‹ฌ๋˜๋Š” ํŒจํ‚ท ์ค‘ /api/Users ๊ฒฝ๋กœ๋กœ POST ์š”์ฒญ์„ ํ•˜๋Š” ํŒจํ‚ท์„ ๋ฐœ๊ฒฌํ•  ์ˆ˜ ์žˆ๋‹ค.

ํ•ด๋‹น ์š”์ฒญ์— ๋Œ€ํ•œ ์‘๋‹ต ํŒจํ‚ท์„ ํ™•์ธํ•ด๋ณด๋ฉด User์˜ ์ •๋ณด๋ฅผ ๋‹ด๊ณ  ์žˆ๋Š” ๊ฐ์ฒด๋ฅผ ํ™•์ธํ•  ์ˆ˜ ์žˆ๊ณ  role ์ด๋ผ๋Š” ์†์„ฑ์ด ์ง€์ •๋œ ๊ฒƒ์„ ํ™•์ธํ•  ์ˆ˜ ์žˆ๋‹ค.

Untitled

์ด๋ฅผ ํ†ตํ•ด admin์˜ ๊ถŒํ•œ์„ ๊ฐ–๊ณ  ์žˆ๋Š” ๊ณ„์ •์„ ์ƒ์„ฑํ•˜๊ธฐ ์œ„ํ•ด /api/Users ๊ฒฝ๋กœ๋กœ role ์†์„ฑ์„ ํฌํ•จ์‹œํ‚จ body๋ฅผ ์ „์†กํ•˜๋ฉด

Untitled

role ์†์„ฑ ๊ฐ’์ด admin ์ธ ๊ณ„์ •์„ ์ƒ์„ฑํ•  ์ˆ˜ ์žˆ๋‹ค.

API-only XSS


XSS Perform aย persisted XSS attack withย <iframe src="javascript:alert(xss)"> without using the frontend application at all.

/api/Products ๊ฒฝ๋กœ์— POST ์š”์ฒญ์„ ๋ณด๋ƒ„์œผ๋กœ์จ ๋ฌผ๊ฑด์„ ๋“ฑ๋กํ•  ์ˆ˜ ์žˆ๋‹ค. postman ์„œ๋น„์Šค๋ฅผ ํ†ตํ•ด ์š”์ฒญ์„ ๋ณด๋‚ด๋ณด์ž.

Untitled

Untitled