天下漏洞,尽知其名
MEDIUM

CVE-2026-107856 CiviForm 信息泄露漏洞

影响认证的 Trusted Intermediary 可越权读取其他组申请人的姓名和邮箱

AI 研判

CiviForm 是用于政府福利申请、可跨多个福利项目复用申请人数据的平台。其 3.33.0 之前版本中,GET /admin/tiDash/editClientForm/:accountId 接口仅校验请求者为 Trusted Intermediary,却未确认目标公民账户属于该请求者所在的 trustedIntermediaryGroup。攻击者可枚举 accountId 读取本组之外申请人的显示名称、姓名与邮箱。

影响范围

CiviForm

CiviForm 3.33.0 之前的版本;3.33.0 已修复。

漏洞详情

漏洞属于越权访问/信息泄露(缺失授权校验)。showEditClientForm 直接以原始 lookupAccount(accountId) 查询账户,未验证该账户是否归属于请求者的 trustedIntermediaryGroup。已认证的 Trusted Intermediary 通过遍历 accountId 即可读取其他组申请人的姓名、邮箱等个人信息。

利用条件与风险

利用前提是攻击者拥有合法的 Trusted Intermediary 账户并通过认证;实战中可批量枚举账户 ID 窃取公民个人身份信息,造成隐私泄露,但需先获得该角色账号。

修复建议

升级至 CiviForm 3.33.0 或更高版本;暂无公开信息说明其他临时缓解措施,可考虑限制 Trusted Intermediary 角色授予并监控异常 accountId 枚举访问。

原始情报

CiviForm simplifies applications for government benefits programs by reusing applicant data across multiple benefit applications. Prior to 3.33.0, GET /admin/tiDash/editClientForm/:accountId verifies that the requester is a Trusted Intermediary but showEditClientForm performs a raw lookupAccount(accountId) without confirming that the citizen account belongs to the requester’s trustedIntermediaryGroup. An authenticated Trusted Intermediary can enumerate accountId values and read the applicant display name, including the citizen’s name and email address, for accounts outside the intermediary’s group. This issue is fixed in version 3.33.0.