SITCON 學生計算機年會 tickets reorder authorizes query.eventId but reorders another event tickets - HITCON ZeroDay

Vulnerability Detail Report

Vulnerability Overview

  • ZDID: ZD-2026-00810
  •  發信 Vendor: SITCON 學生計算機年會
  • Title: SITCON 學生計算機年會 tickets reorder authorizes query.eventId but reorders another event tickets
  • Introduction: The public SITCON tickets reorder route authorizes eventAdmin access from query.eventId, but the handler reorders the submitted ticket IDs without verifying that their event matches the authorized event.

處理狀態

目前狀態

公開
Last Update : 2026/09/19
  • 新提交
  • 已審核
  • 已通報
  • 已修補
  • 未複測
  • 公開

處理歷程

  • 2026/06/03 19:52:22 : 新提交 (由 老狼 更新此狀態)
  • 2026/06/10 12:49:23 : 審核中 (由 HITCON ZeroDay 服務團隊 更新此狀態)
  • 2026/09/18 15:33:45 : 已修補 (由 組織帳號 更新此狀態)
  • 2026/09/19 03:00:15 : 公開 (由 HITCON ZeroDay 平台自動更新)

詳細資料

  • ZDID:ZD-2026-00810
  • 通報者:skyknow (老狼)
  • 風險:中
  • 類型:存取控制缺陷 (Broken Access Control)

參考資料

攻擊者可經由該漏洞取得、修改、刪除系統中的其他使用者的資料,或連線至高權限使用者的頁面。

OWASP Top 10 - 2017 A5 - Broken Access Control
https://www.owasp.org/index.php/Top_10-2017_A5-Broken_Access_Control

CWE-284: Improper Access Control
https://cwe.mitre.org/data/definitions/284.html
(本欄位資訊由系統根據漏洞類別自動產生,做為漏洞參考資料。)

相關網址

https://zeroday.hitcon.org/bug-bounty/list
https://github.com/sitcon-tw/tickets
https://github.com/sitcon-tw/tickets/blob/db4a3500c0331bdc5c204808399c52aa024b87e8/backend/routes/admin/tickets.ts
https://github.com/sitcon-tw/tickets/blob/db4a3500c0331bdc5c204808399c52aa024b87e8/backend/middleware/auth.ts
https://github.com/sitcon-tw/tickets/blob/db4a3500c0331bdc5c204808399c52aa024b87e8/backend/schemas.ts

敘述

Summary

圖片

The public sitcon-tw/tickets backend has an admin ticket reorder route:

PUT /api/admin/tickets/reorder

The route uses requireEventAccess. That middleware authorizes eventAdmin users by checking:

query.eventId || params.id || body.eventId

For the reorder route, the body schema only contains tickets: [{ id, order }]. The handler loads those ticket IDs, validates that all submitted tickets belong to the same event, and then updates their order. It does not verify that the target tickets' event is the same event that satisfied requireEventAccess.

A local source model therefore shows this mismatch:

PUT /api/admin/tickets/reorder?eventId=owned-event
body tickets belong to victim-event
eventAdmin permissions = [owned-event]

guard authorizes owned-event
handler reorders victim-event tickets

If deployed as reviewed, an event-scoped organizer may be able to reorder tickets for an unrelated event.

Source evidence

  • backend/middleware/auth.ts reads query?.eventId || params?.id || body?.eventId.
  • backend/routes/admin/tickets.ts protects PUT /tickets/reorder with preHandler: requireEventAccess.
  • backend/schemas.ts defines TicketReorderBodySchema with only ticket IDs and order values, not a trusted target event.
  • backend/routes/admin/tickets.ts loads tickets by submitted IDs and selects their eventId.
  • backend/routes/admin/tickets.ts only checks that all submitted tickets share one event.
  • backend/routes/admin/tickets.ts updates the submitted ticket IDs without checking that their event matches the authorized event.

Local-only reproduction

圖片

I validated the control flow using local static modeling only:

python3 findings/20260603-1523-hitcon-sitcon-ticket-reorder-eventid-mismatch/local-repro.py

Result:

{
  "observed_candidate_behavior": true,
  "network_requests": 0,
  "validation_mode": "LOCAL_SOURCE_STATIC_MODEL"
}

Impact

Ticket ordering affects ticket presentation and registration flow. Cross-event reorder can let an event-scoped organizer alter another event's ticket order, which can disrupt ticket sales UX or change which tickets are promoted or de-emphasized in the registration interface.

This report is intentionally conservative: I validated public source and local control flow only. I did not prove live SITCON production exploitability.

Safety boundary

圖片

This report is based on public source and local-only analysis. I did not log in to SITCON, request SITCON production/private endpoints, use a real event ID/ticket ID/registration/order value, reorder any real ticket, access real event/ticket/registration/email/form data, use scanners/fuzzing/DoS, contact SITCON, publish an issue, or open a PR.

修補建議

Derive the target event from the submitted ticket IDs and authorize that event before updating. The event used for authorization should be identical to the event affected by the reorder operation.

擷圖

留言討論

聯絡組織

 發送私人訊息
您也可以透過私人訊息的方式與組織聯繫,討論有關於這個漏洞的相關資訊。
;