Skip to content
1

1

github.com • September 7, 2026

The application exposes a user creation endpoint, saveuser.php , that does not enforce server-side authentication or authorization. By deleting the session cookie or otherwise sending the request without a valid authenticated session, an attacker can still submit a crafted request, modify the position parameter, and create a new account with administrative privileges.

This issue is caused by missing authentication and authorization checks in the backend. Client-side form controls and restrictions do not prevent direct requests to the vulnerable endpoint.

An unauthenticated or low-privileged attacker may be able to:

Create a new administrator account

Gain administrative access to the backend

View, modify, or delete sensitive data

Execute further privileged actions as an administrator

4. Vulnerability Type

CWE-306: Missing Authentication for Critical Function

CWE-862: Missing Authorization

CWE-269: Improper Privilege Management

The backend endpoint saveuser.php accepts user-supplied role data without validating whether the current session is authenticated or authorized to create administrator accounts. The page-level control in sidebar.php only checks whether a user is logged in at the UI level, not whether the request is allowed at the backend.

As a result, the application trusts a client-controlled field for privilege assignment.

6. Affected Components

7. Reproduction Steps

Open the user creation function in the application.

Delete the session cookie or otherwise send the request without a valid authenticated session.

Intercept or directly craft the request to saveuser.php in Burp Repeater.

Modify the position parameter from a normal role to admin .

Observe that the server accepts the request and creates a new administrator account.

Step 1: Intercepting the request

Step 2: Changing the role to admin

Step 3: Server accepts the request

Step 4: Confirming the new admin account

TODO: Publish a public advisory page or disclosure note that describes the vulnerability and includes the affected product and version information.

TODO: Publish a public advisory page or disclosure note that describes the vulnerability and includes the affected product and version information.

The CVE record requires at least one public reference that is accessible from the Internet and contains the minimum required information for the entry.

10. Recommended Remediation

Enforce server-side authorization in saveuser.php .

Require an authenticated administrator session before allowing account creation.

Do not trust the position parameter from the client.

Restrict administrator role assignment to authorized administrative workflows only.

Add audit logging for all account creation and privilege changes.

Apply CSRF protection to sensitive state-changing requests.

11. English CVE Description

In Simple Traffic Offense System using PHP with Source Code v1.0, the saveuser.php endpoint does not perform server-side authentication or authorization checks before processing account creation requests. An attacker can delete the session cookie or submit the request without a valid authenticated session, modify the position parameter in a crafted request, and create a new administrator account. This issue results in privilege escalation and allows the attacker to gain administrative access to the application.

在 Simple Traffic Offense System using PHP with Source Code v1.0 中, saveuser.php 接口缺少服务端认证和授权校验,攻击者可以通过删除 Cookie 或在未登录状态下直接篡改 position 参数创建管理员账户,从而实现权限提升并接管后台。