That's the part I don't get. Once the code dies it's done. What exactly can you do now, if no code is even running?
That's the part I don't get. Once the code dies it's done. What exactly can you do now, if no code is even running?
1. Parse user.
2. Parse password.
3. Create session object from user and password.
4. Parse JSON. (Crashes here.)
5. Update session and do some other security stuff.
The problem is that they're creating a persistent session object ahead of when the JSON parameters are being decoded, which leaves a (partially initialized, persisting-outside-of-function) session object without having gone through the full authentication flow.
The problem is that they're creating permanent objects ahead of a full validation on the data necessary to actually properly initialize the object.
(I think the OP may have been a little vague because that's probably specific enough to identify the vuln with a scanner and a hunch.)
I don't do PHP. It just sounds incredible to me that so little isolation seems to exist.