Vulnerability Detail Report
Vulnerability Overview
- ZDID: ZD-2026-00805
- Vendor: SITCON 學生計算機年會
- Title: SITCON 學生計算機年會 tickets eventAdmin registration export lacks event scoping
- Introduction: The public SITCON tickets backend appears to let eventAdmin users reach a registration export route that lacks event-scoped authorization and can export all matched registrations when eventId is omitted.
處理狀態
目前狀態
-
新提交
-
已審核
-
已通報
-
已修補
-
未複測
-
公開
處理歷程
- 2026/06/03 19:41:51 : 新提交 (由 老狼 更新此狀態)
- 2026/06/10 12:47:46 : 審核中 (由 HITCON ZeroDay 服務團隊 更新此狀態)
- 2026/09/18 14:27:05 : 已修補 (由 組織帳號 更新此狀態)
- 2026/09/19 03:00:04 : 公開 (由 HITCON ZeroDay 平台自動更新)
詳細資料
- ZDID:ZD-2026-00805
- 通報者:skyknow (老狼)
- 風險:中
- 類型:存取控制缺陷 (Broken Access Control)
參考資料
OWASP Top 10 - 2017 A5 - Broken Access Control
https://www.owasp.org/index.php/Top_10-2017_A5-Broken_Access_Control
CWE-284: Improper Access Control
https://cwe.mitre.org/data/definitions/284.html
相關網址
https://github.com/sitcon-tw/tickets
https://github.com/sitcon-tw/tickets/blob/db4a3500c0331bdc5c204808399c52aa024b87e8/backend/routes/admin/registrations.ts#L421-L458
https://github.com/sitcon-tw/tickets/blob/db4a3500c0331bdc5c204808399c52aa024b87e8/backend/routes/admin.ts#L17
https://github.com/sitcon-tw/tickets/blob/db4a3500c0331bdc5c204808399c52aa024b87e8/backend/middleware/auth.ts#L151
敘述
Summary
The public sitcon-tw/tickets backend mounts adminRoutes under /api/admin and protects that router with requireAdminOrEventAdmin. That guard allows both admin and eventAdmin roles.
Most registration admin routes apply event-level checks such as requireEventAccess or requireEventAccessViaRegistrationId, but GET /api/admin/registrations/export does not. The export handler accepts optional eventId and status query parameters. If eventId is omitted, it uses an empty Prisma filter and exports all matched registrations.
If the deployed system follows this source, an eventAdmin assigned to one event may be able to export registration data for unrelated events.
Source evidence
backend/routes/index.ts:8mountsadminRoutesunder/api/admin.backend/routes/admin.ts:17installsrequireAdminOrEventAdmin.backend/middleware/auth.ts:151definesrequireAdminOrEventAdminasrequireRole(["admin", "eventAdmin"]).backend/routes/admin/registrations.ts:421definesGET /registrations/export.backend/routes/admin/registrations.ts:426reads optional query fields:eventId,status, andformat.backend/routes/admin/registrations.ts:437-438starts with an empty filter and only applieswhere.eventId = eventIdwheneventIdis supplied.- The export includes registration email, event name, ticket name, ticket price, referral email, created timestamp, and custom form-data fields.
Local-only reproduction
I validated the source path using a local static model only:
python3 findings/20260603-1123-hitcon-sitcon-tickets-eventadmin-registration-export/local-repro.py
The script checks route mounting, role guard, missing event-level route guard, optional eventId, empty export filter, conditional event filter, and exported data fields. It reports:
{
"observed_candidate_behavior": true,
"network_requests": 0,
"validation_mode": "LOCAL_SOURCE_STATIC_MODEL"
}
Impact
Registration export data can contain participant email addresses, event and ticket details, referral email, registration timestamps, and custom registration answers. Cross-event access to that export would expose participant personal data and event-specific form responses to organizers who should only manage their assigned event.
Safety boundary
This report is based on public source and local static validation. I did not log in to SITCON, request SITCON production/private endpoints, export or access real registration data, send email, trigger Google Sheets sync, use scanners/fuzzing/DoS, contact SITCON, publish an issue, or open a PR.
修補建議
Require event-scoped authorization for export. For eventAdmin, require an eventId, validate it with requireEventAccess, and force the export query to the authorized event. If global export is needed, restrict the no-eventId path to admin only.