最新消息:雨落星辰是一个专注网站SEO优化、网站SEO诊断、搜索引擎研究、网络营销推广、网站策划运营及站长类的自媒体原创博客

Regular users logs in as ADMIN if Admin logged in recently

programmeradmin3浏览0评论

Just found a crazy vulnerability and have no idea how to fix it.

Here is a situation:

  1. Admin logs in to a website.
  2. Regular user logs in using their credentials within the next few minutes
  3. Instead of logging in to their profile, they get access to admin resources. Their username is reflected as admin and they have access to all the features.

Why is this happening and how to stop it?

That's not the first time it happens and I am really concerned about it. I am using optimizepress plugin for creating custom login page. Don't know if it may be related to the problem

发布评论

评论列表(0)

  1. 暂无评论