SITCON 學生計算機年會 tickets event form-field handlers continue after failed event access - HITCON ZeroDay

Vulnerability Detail Report

Vulnerability Overview

  • ZDID: ZD-2026-00806
  •  發信 Vendor: SITCON 學生計算機年會
  • Title: SITCON 學生計算機年會 tickets event form-field handlers continue after failed event access
  • Introduction: Several public SITCON tickets event form-field admin handlers manually call requireEventAccess but continue into read/write logic after the guard sends a denial response.

處理狀態

目前狀態

公開
Last Update : 2026/09/19
  • 新提交
  • 已審核
  • 已通報
  • 已修補
  • 未複測
  • 公開

處理歷程

  • 2026/06/03 19:45:09 : 新提交 (由 老狼 更新此狀態)
  • 2026/06/10 12:48:12 : 審核中 (由 HITCON ZeroDay 服務團隊 更新此狀態)
  • 2026/09/18 15:32:03 : 已修補 (由 組織帳號 更新此狀態)
  • 2026/09/19 03:00:07 : 公開 (由 HITCON ZeroDay 平台自動更新)

詳細資料

  • ZDID:ZD-2026-00806
  • 通報者:skyknow (老狼)
  • 風險:中
  • 類型:存取控制缺陷 (Broken Access Control)

參考資料

攻擊者可經由該漏洞取得、修改、刪除系統中的其他使用者的資料,或連線至高權限使用者的頁面。

OWASP Top 10 - 2017 A5 - Broken Access Control
https://www.owasp.org/index.php/Top_10-2017_A5-Broken_Access_Control

CWE-284: Improper Access Control
https://cwe.mitre.org/data/definitions/284.html
(本欄位資訊由系統根據漏洞類別自動產生,做為漏洞參考資料。)

相關網址

https://zeroday.hitcon.org/bug-bounty/list
https://github.com/sitcon-tw/tickets
https://github.com/sitcon-tw/tickets/blob/db4a3500c0331bdc5c204808399c52aa024b87e8/backend/routes/admin/eventFormFields.ts
https://github.com/sitcon-tw/tickets/blob/db4a3500c0331bdc5c204808399c52aa024b87e8/backend/middleware/auth.ts#L151-L181
https://github.com/sitcon-tw/tickets/blob/db4a3500c0331bdc5c204808399c52aa024b87e8/backend/routes/admin.ts#L17

敘述

Summary

圖片

The public sitcon-tw/tickets backend allows both admin and eventAdmin roles into the /api/admin router through requireAdminOrEventAdmin.

Several event form-field admin handlers then call requireEventAccess manually inside the handler body. When requireEventAccess denies an eventAdmin that is not authorized for the target event, it sends a denial response, but the caller does not check reply.sent or immediately return before continuing.

If the deployed system follows this source, an event-scoped organizer may be able to reach form-field create, list, or reorder logic for an unrelated event despite the event access guard sending a denial response.

Source evidence

  • backend/routes/admin.ts:17 installs the top-level admin router guard.
  • backend/middleware/auth.ts:151 allows eventAdmin into that router.
  • backend/middleware/auth.ts:181 is the unauthorized eventAdmin denial path.
  • backend/routes/admin/eventFormFields.ts:20 defines create form-field.
  • backend/routes/admin/eventFormFields.ts:35 calls requireEventAccess manually inside create.
  • backend/routes/admin/eventFormFields.ts:67 reaches prisma.eventFormFields.create.
  • backend/routes/admin/eventFormFields.ts:359 defines list form-fields.
  • backend/routes/admin/eventFormFields.ts:375 calls requireEventAccess manually inside list.
  • backend/routes/admin/eventFormFields.ts:397 reaches prisma.eventFormFields.findMany.
  • backend/routes/admin/eventFormFields.ts:431 defines reorder form-fields.
  • backend/routes/admin/eventFormFields.ts:446 calls requireEventAccess manually inside reorder.
  • backend/routes/admin/eventFormFields.ts:490 reaches prisma.eventFormFields.update.

Local-only reproduction

圖片

I validated the source path using a local static model only:

python3 findings/20260603-1153-hitcon-sitcon-event-form-fields-auth-continues/local-repro.py

The script checks guard placement, the denial response path, missing post-guard reply.sent checks, and subsequent read/write operations. It reports:

{
  "observed_candidate_behavior": true,
  "network_requests": 0,
  "validation_mode": "LOCAL_SOURCE_STATIC_MODEL"
}

Impact

Event form fields define registration form requirements, prompts, options, ordering, and conditional behavior. Cross-event access to this surface could let an event-scoped organizer read another event's form schema/configuration or alter registration form fields for an event they should not manage.

This report is intentionally conservative: I validated public source and local control flow only. I did not prove live production exploitability.

Safety boundary

圖片

This report is based on public source and local static validation. I did not log in to SITCON, request SITCON production/private endpoints, create/list/reorder/mutate any real form field, access real registration data, use scanners/fuzzing/DoS, contact SITCON, publish an issue, or open a PR.

修補建議

Use preHandler: requireEventAccess for these routes so Fastify stops the request before the handler body, or immediately return after each manual guard call when reply.sent is true. Prefer the route preHandler style used by neighboring admin routes.

擷圖

留言討論

聯絡組織

 發送私人訊息
您也可以透過私人訊息的方式與組織聯繫,討論有關於這個漏洞的相關資訊。
;