Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

base64Captcha v1.3.6的bug导致simple-admin所有可选验证码的场景验证码可绕过 #270

Closed
aac3476 opened this issue Mar 4, 2024 · 5 comments

Comments

@aac3476
Copy link

aac3476 commented Mar 4, 2024

例如:https://github.com/suyuan32/simple-admin-member-api/blob/6cceafa1077fc3f921fb24f7ce596e3bb894f573/internal/logic/publicmember/login_logic.go#L48

开关失效 可以通过传空验证码信息绕过验证码验证

相关问题链接
mojocn/base64Captcha#122

建议降级base64Captcha版本

@suyuan32
Copy link
Owner

suyuan32 commented Mar 4, 2024

api不是有校验不能为空嘛

@suyuan32
Copy link
Owner

suyuan32 commented Mar 4, 2024

image

@suyuan32
Copy link
Owner

suyuan32 commented Mar 4, 2024

好吧omitempty 了

@suyuan32
Copy link
Owner

suyuan32 commented Mar 4, 2024

@suyuan32 suyuan32 closed this as completed Mar 4, 2024
@aac3476
Copy link
Author

aac3476 commented Mar 5, 2024

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants