We read every piece of feedback, and take your input very seriously.
To see all available qualifiers, see our documentation.
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
1.登录admin账号,增加一个用户名为test的用户。 2.使用test账号加错误密码进行登录会出现“账号或者密码错误” 3.使用不存在的账号(这里使用test1),则会出现“用户不存在或被禁用”
The text was updated successfully, but these errors were encountered:
修复后台登录页面的用户名枚举漏洞 #47
4f4dfa1
No branches or pull requests
1.登录admin账号,增加一个用户名为test的用户。
![image](https://private-user-images.githubusercontent.com/105919489/353780634-7fca459e-5847-41ee-b298-afc3982b07bc.png?jwt=eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJpc3MiOiJnaXRodWIuY29tIiwiYXVkIjoicmF3LmdpdGh1YnVzZXJjb250ZW50LmNvbSIsImtleSI6ImtleTUiLCJleHAiOjE3MzkwNDA1MzAsIm5iZiI6MTczOTA0MDIzMCwicGF0aCI6Ii8xMDU5MTk0ODkvMzUzNzgwNjM0LTdmY2E0NTllLTU4NDctNDFlZS1iMjk4LWFmYzM5ODJiMDdiYy5wbmc_WC1BbXotQWxnb3JpdGhtPUFXUzQtSE1BQy1TSEEyNTYmWC1BbXotQ3JlZGVudGlhbD1BS0lBVkNPRFlMU0E1M1BRSzRaQSUyRjIwMjUwMjA4JTJGdXMtZWFzdC0xJTJGczMlMkZhd3M0X3JlcXVlc3QmWC1BbXotRGF0ZT0yMDI1MDIwOFQxODQzNTBaJlgtQW16LUV4cGlyZXM9MzAwJlgtQW16LVNpZ25hdHVyZT0wZTk1ZmJjOGYxZTkyNzdkOGMzZDI5MTAzODEzNjA5ZTIyNjc1YmMzNmY2NThlOGEzZTM2MGEyNmZmMDMyNjhmJlgtQW16LVNpZ25lZEhlYWRlcnM9aG9zdCJ9.FKIo4cnUHxGjZwjyls8LO7D82PVt6FBVvTRgRIMx3c0)
![image](https://private-user-images.githubusercontent.com/105919489/353780940-41e5f7d9-c410-42bd-906b-414a9a2cad91.png?jwt=eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJpc3MiOiJnaXRodWIuY29tIiwiYXVkIjoicmF3LmdpdGh1YnVzZXJjb250ZW50LmNvbSIsImtleSI6ImtleTUiLCJleHAiOjE3MzkwNDA1MzAsIm5iZiI6MTczOTA0MDIzMCwicGF0aCI6Ii8xMDU5MTk0ODkvMzUzNzgwOTQwLTQxZTVmN2Q5LWM0MTAtNDJiZC05MDZiLTQxNGE5YTJjYWQ5MS5wbmc_WC1BbXotQWxnb3JpdGhtPUFXUzQtSE1BQy1TSEEyNTYmWC1BbXotQ3JlZGVudGlhbD1BS0lBVkNPRFlMU0E1M1BRSzRaQSUyRjIwMjUwMjA4JTJGdXMtZWFzdC0xJTJGczMlMkZhd3M0X3JlcXVlc3QmWC1BbXotRGF0ZT0yMDI1MDIwOFQxODQzNTBaJlgtQW16LUV4cGlyZXM9MzAwJlgtQW16LVNpZ25hdHVyZT0xMWYzNDkwMzQ2OWZkZjY0ZDk5YTcxMjNkZGE5MDJjODdjYjM1OTYzZjIwYmRjNzMyMTI4YjQ3OTlkODdiNjViJlgtQW16LVNpZ25lZEhlYWRlcnM9aG9zdCJ9.KOt6mNC-QxdmYYTz1xKY1NFM4IfayErRYy067Z_gQdM)
2.使用test账号加错误密码进行登录会出现“账号或者密码错误”
3.使用不存在的账号(这里使用test1),则会出现“用户不存在或被禁用”
The text was updated successfully, but these errors were encountered: