Vulnerability Detail Report
Vulnerability Overview
- ZDID: ZD-2026-00734
- Vendor: {Zuvio IRS}
- Title: Zuvio課堂系統 - 繳交作業 API 缺乏伺服器端截止時間驗證(可在截止日後補交)
- Introduction: *平台在學生繳交作業的功能中,網頁前端雖然會在作業截止後將「繳交」按鈕隱藏或停用,然而後端 API 路由在接收 POST 請求時,並未在伺服器端(Server-side)檢查當前時間是否已超過該 bulletin_id 的截止時間。
處理狀態
目前狀態
-
新提交
-
已審核
-
已通報
-
未回報修補狀況
-
未複測
-
公開
處理歷程
- 2026/05/22 11:23:38 : 新提交 (由 Rduan 更新此狀態)
- 2026/05/26 17:11:52 : 新提交 (由 Rduan 更新此狀態)
- 2026/05/28 15:49:32 : 審核完成 (由 HITCON ZeroDay 服務團隊 更新此狀態)
- 2026/05/28 18:17:53 : 修補中 (由 HITCON ZeroDay 服務團隊 更新此狀態)
- 2026/05/28 18:17:53 : 審核完成 (由 HITCON ZeroDay 服務團隊 更新此狀態)
- 2026/05/28 18:17:53 : 修補中 (由 HITCON ZeroDay 服務團隊 更新此狀態)
- 2026/07/22 03:00:06 : 公開 (由 HITCON ZeroDay 平台自動更新)
詳細資料
- ZDID:ZD-2026-00734
- 通報者:Rduanchen (Rduan)
- 風險:低
- 類型:邏輯漏洞 (Logic Flaws)
參考資料
漏洞說明: OWASP - Testing for business logic
https://www.owasp.org/index.php/Testing_for_business_logic
漏洞說明: CWE-840: Business Logic Errors
https://cwe.mitre.org/data/definitions/840.html
相關網址
敘述
Vulnerability Title
Improper Enforcement of Assessment Deadline via Missing Server-Side Validation in Homework Submission API
Target Vendor & Product
- Vendor: Learning Digital (學悅科技)
- Product / Platform: Zuvio IRS System (irs.zuvio.com.tw)
Vulnerability Description
A business logic vulnerability exists in the Zuvio classroom interaction platform. While the user interface (UI) on the client side properly hides or disables the "Submit" button once a homework or quiz deadline has passed, the backend API endpoint does not perform any corresponding date or time validation on the server side.
An authenticated user (student) can completely bypass the front-end restriction by making a direct HTTP POST request to the submission endpoint. Because the application processes incoming requests without checking whether the current server timestamp exceeds the deadline associated with the specified bulletin_id, students are able to successfully upload and submit assignments long after the official due date. This flaw undermines the behavioral integrity and grading fairness of the educational platform.
Affected Endpoint
- HTTP Method:
POST - URL:
https://irs.zuvio.com.tw/app_v2/submitHmwk - Content-Type:
application/x-www-form-urlencoded
Proof of Concept (PoC) / Replication Steps
- Locate an assignment or quiz (
bulletin_id) that has already passed its official deadline. The web UI should indicate that submission is closed. - Upload the target file using the standard file upload API endpoint (
/upload/file_s/file_question) to obtain a valid remote filename (s3_file_name) and object URL (s3_file_url). - Using an intercepting proxy (e.g., Burp Suite) or a custom script (e.g., Python
requests), craft a direct HTTP POST request to the submission endpoint with legitimate active session cookies (PHPSESSID) and authorization tokens (accessToken). - Include the parameters associated with the past-due assignment in the payload structure:
POST /app_v2/submitHmwk HTTP/1.1
Host: irs.zuvio.com.tw
Content-Type: application/x-www-form-urlencoded; charset=UTF-8
Cookie: PHPSESSID=VALID_SESSION_COOKIE
user_id=TARGET_USER_ID&accessToken=VALID_ACCESS_TOKEN&course_id=TARGET_COURSE_ID&bulletin_id=PAST_DUE_BULLETIN_ID&origin_file_name=sample.c&s3_file_name=irs_uploaded_sample_hash.c&s3_file_url=https%3A%2F%2Fs3.hicloud.net.tw%2Fzuvio.public%2F...&file_type=c
- The server evaluates the payload and returns an HTTP 200 OK response with a JSON body indicating a successful operation:
{
"status": true,
"hmwk": {
"id": "1278714",
"course_id": "1512664",
"bulletin_id": "495832",
"user_id": "3917810",
...
},
"msg": "OK"
}
- Verifying the student profile on the web portal confirms that the file was appended and recognized as a recorded submission despite the expired status.
Impact
An authenticated malicious actor or standard user can turn in late assignments or exams without penalty, introducing unexpected data states into the system. This breaks structural expectations of access control lists where access permissions are bound to temporal conditions.