Vulnerability Detail Report
Vulnerability Overview
- ZDID: ZD-2026-00810
- Vendor: SITCON 學生計算機年會
- Title: SITCON 學生計算機年會 tickets reorder authorizes query.eventId but reorders another event tickets
- Introduction: The public SITCON tickets reorder route authorizes eventAdmin access from query.eventId, but the handler reorders the submitted ticket IDs without verifying that their event matches the authorized event.
處理狀態
目前狀態
-
新提交
-
已審核
-
已通報
-
已修補
-
未複測
-
公開
處理歷程
- 2026/06/03 19:52:22 : 新提交 (由 老狼 更新此狀態)
- 2026/06/10 12:49:23 : 審核中 (由 HITCON ZeroDay 服務團隊 更新此狀態)
- 2026/09/18 15:33:45 : 已修補 (由 組織帳號 更新此狀態)
- 2026/09/19 03:00:15 : 公開 (由 HITCON ZeroDay 平台自動更新)
詳細資料
- ZDID:ZD-2026-00810
- 通報者:skyknow (老狼)
- 風險:中
- 類型:存取控制缺陷 (Broken Access Control)
參考資料
OWASP Top 10 - 2017 A5 - Broken Access Control
https://www.owasp.org/index.php/Top_10-2017_A5-Broken_Access_Control
CWE-284: Improper Access Control
https://cwe.mitre.org/data/definitions/284.html
相關網址
https://github.com/sitcon-tw/tickets
https://github.com/sitcon-tw/tickets/blob/db4a3500c0331bdc5c204808399c52aa024b87e8/backend/routes/admin/tickets.ts
https://github.com/sitcon-tw/tickets/blob/db4a3500c0331bdc5c204808399c52aa024b87e8/backend/middleware/auth.ts
https://github.com/sitcon-tw/tickets/blob/db4a3500c0331bdc5c204808399c52aa024b87e8/backend/schemas.ts
敘述
Summary
The public sitcon-tw/tickets backend has an admin ticket reorder route:
PUT /api/admin/tickets/reorder
The route uses requireEventAccess. That middleware authorizes eventAdmin users by checking:
query.eventId || params.id || body.eventId
For the reorder route, the body schema only contains tickets: [{ id, order }]. The handler loads those ticket IDs, validates that all submitted tickets belong to the same event, and then updates their order. It does not verify that the target tickets' event is the same event that satisfied requireEventAccess.
A local source model therefore shows this mismatch:
PUT /api/admin/tickets/reorder?eventId=owned-event
body tickets belong to victim-event
eventAdmin permissions = [owned-event]
guard authorizes owned-event
handler reorders victim-event tickets
If deployed as reviewed, an event-scoped organizer may be able to reorder tickets for an unrelated event.
Source evidence
backend/middleware/auth.tsreadsquery?.eventId || params?.id || body?.eventId.backend/routes/admin/tickets.tsprotectsPUT /tickets/reorderwithpreHandler: requireEventAccess.backend/schemas.tsdefinesTicketReorderBodySchemawith only ticket IDs and order values, not a trusted target event.backend/routes/admin/tickets.tsloads tickets by submitted IDs and selects theireventId.backend/routes/admin/tickets.tsonly checks that all submitted tickets share one event.backend/routes/admin/tickets.tsupdates the submitted ticket IDs without checking that their event matches the authorized event.
Local-only reproduction
I validated the control flow using local static modeling only:
python3 findings/20260603-1523-hitcon-sitcon-ticket-reorder-eventid-mismatch/local-repro.py
Result:
{
"observed_candidate_behavior": true,
"network_requests": 0,
"validation_mode": "LOCAL_SOURCE_STATIC_MODEL"
}
Impact
Ticket ordering affects ticket presentation and registration flow. Cross-event reorder can let an event-scoped organizer alter another event's ticket order, which can disrupt ticket sales UX or change which tickets are promoted or de-emphasized in the registration interface.
This report is intentionally conservative: I validated public source and local control flow only. I did not prove live SITCON production exploitability.
Safety boundary
This report is based on public source and local-only analysis. I did not log in to SITCON, request SITCON production/private endpoints, use a real event ID/ticket ID/registration/order value, reorder any real ticket, access real event/ticket/registration/email/form data, use scanners/fuzzing/DoS, contact SITCON, publish an issue, or open a PR.
修補建議
Derive the target event from the submitted ticket IDs and authorize that event before updating. The event used for authorization should be identical to the event affected by the reorder operation.