ad: k1jek

Regarding the authentication issue in the support center

Discussion in 'QRZ Site Community Help Center' started by BG7ZDQ, Mar 28, 2024.

ad: L-HROutlet
ad: l-rl
ad: Left-2
ad: L-MFJ
ad: Radclub22-2
ad: Left-3
ad: abrind-2
  1. BG7ZDQ

    BG7ZDQ Ham Member QRZ Page

    Just now I tried to change my call sign in the support center.

    After submitting my request, I found that the work order feedback page provided by QRZ and the attachments uploaded by the user were not authenticated, which means that non-logged-in/unauthorized users can access the user's work order and submitted attachments through parameter enumeration, which may include the user's identity and license documents. This is very dangerous. Moreover, the attachment interface does not impose any restrictions at all, and its parameters are extremely simple, making it easier for illegal access to the data.

    I hope that the forum maintainers can promptly notice these issues and take corresponding measures.

    Thank you!
     
  2. K8VHL

    K8VHL Platinum Subscriber Volunteer Moderator Platinum Subscriber QRZ Page

    Please inform the forum maintainers about your concerns by email at editor@qrz.com
     

Share This Page

ad: AbAuRe-1