SITCON 學生計算機年會 tickets eventAdmin registration export lacks event scoping - HITCON ZeroDay

Vulnerability Detail Report

Vulnerability Overview

  • ZDID: ZD-2026-00805
  •  發信 Vendor: SITCON 學生計算機年會
  • Title: SITCON 學生計算機年會 tickets eventAdmin registration export lacks event scoping
  • Introduction: The public SITCON tickets backend appears to let eventAdmin users reach a registration export route that lacks event-scoped authorization and can export all matched registrations when eventId is omitted.

處理狀態

目前狀態

公開
Last Update : 2026/09/19
  • 新提交
  • 已審核
  • 已通報
  • 已修補
  • 未複測
  • 公開

處理歷程

  • 2026/06/03 19:41:51 : 新提交 (由 老狼 更新此狀態)
  • 2026/06/10 12:47:46 : 審核中 (由 HITCON ZeroDay 服務團隊 更新此狀態)
  • 2026/09/18 14:27:05 : 已修補 (由 組織帳號 更新此狀態)
  • 2026/09/19 03:00:04 : 公開 (由 HITCON ZeroDay 平台自動更新)

詳細資料

  • ZDID:ZD-2026-00805
  • 通報者:skyknow (老狼)
  • 風險:中
  • 類型:存取控制缺陷 (Broken Access Control)

參考資料

攻擊者可經由該漏洞取得、修改、刪除系統中的其他使用者的資料,或連線至高權限使用者的頁面。

OWASP Top 10 - 2017 A5 - Broken Access Control
https://www.owasp.org/index.php/Top_10-2017_A5-Broken_Access_Control

CWE-284: Improper Access Control
https://cwe.mitre.org/data/definitions/284.html
(本欄位資訊由系統根據漏洞類別自動產生,做為漏洞參考資料。)

相關網址

https://zeroday.hitcon.org/bug-bounty/list
https://github.com/sitcon-tw/tickets
https://github.com/sitcon-tw/tickets/blob/db4a3500c0331bdc5c204808399c52aa024b87e8/backend/routes/admin/registrations.ts#L421-L458
https://github.com/sitcon-tw/tickets/blob/db4a3500c0331bdc5c204808399c52aa024b87e8/backend/routes/admin.ts#L17
https://github.com/sitcon-tw/tickets/blob/db4a3500c0331bdc5c204808399c52aa024b87e8/backend/middleware/auth.ts#L151

敘述

Summary

圖片

The public sitcon-tw/tickets backend mounts adminRoutes under /api/admin and protects that router with requireAdminOrEventAdmin. That guard allows both admin and eventAdmin roles.

Most registration admin routes apply event-level checks such as requireEventAccess or requireEventAccessViaRegistrationId, but GET /api/admin/registrations/export does not. The export handler accepts optional eventId and status query parameters. If eventId is omitted, it uses an empty Prisma filter and exports all matched registrations.

If the deployed system follows this source, an eventAdmin assigned to one event may be able to export registration data for unrelated events.

Source evidence

  • backend/routes/index.ts:8 mounts adminRoutes under /api/admin.
  • backend/routes/admin.ts:17 installs requireAdminOrEventAdmin.
  • backend/middleware/auth.ts:151 defines requireAdminOrEventAdmin as requireRole(["admin", "eventAdmin"]).
  • backend/routes/admin/registrations.ts:421 defines GET /registrations/export.
  • backend/routes/admin/registrations.ts:426 reads optional query fields: eventId, status, and format.
  • backend/routes/admin/registrations.ts:437-438 starts with an empty filter and only applies where.eventId = eventId when eventId is supplied.
  • The export includes registration email, event name, ticket name, ticket price, referral email, created timestamp, and custom form-data fields.

Local-only reproduction

圖片

I validated the source path using a local static model only:

python3 findings/20260603-1123-hitcon-sitcon-tickets-eventadmin-registration-export/local-repro.py

The script checks route mounting, role guard, missing event-level route guard, optional eventId, empty export filter, conditional event filter, and exported data fields. It reports:

{
  "observed_candidate_behavior": true,
  "network_requests": 0,
  "validation_mode": "LOCAL_SOURCE_STATIC_MODEL"
}

Impact

Registration export data can contain participant email addresses, event and ticket details, referral email, registration timestamps, and custom registration answers. Cross-event access to that export would expose participant personal data and event-specific form responses to organizers who should only manage their assigned event.

Safety boundary

圖片

This report is based on public source and local static validation. I did not log in to SITCON, request SITCON production/private endpoints, export or access real registration data, send email, trigger Google Sheets sync, use scanners/fuzzing/DoS, contact SITCON, publish an issue, or open a PR.

修補建議

Require event-scoped authorization for export. For eventAdmin, require an eventId, validate it with requireEventAccess, and force the export query to the authorized event. If global export is needed, restrict the no-eventId path to admin only.

擷圖

留言討論

聯絡組織

 發送私人訊息
您也可以透過私人訊息的方式與組織聯繫,討論有關於這個漏洞的相關資訊。
;