Executive brief
GouGuOA is an open-source office management system used for enterprise operations including HR, finance, and project management. A mass assignment vulnerability in the personal profile editing endpoint allows authenticated users to modify sensitive database fields beyond their profile data, potentially escalating privileges or gaining unauthorized access to administrative functions.
Technical details
A mass assignment (batch assignment) vulnerability exists in the edit_personal endpoint (/home/index/edit_personal) of GouGuOA versions up to 5.10.0 and 6.0.1. The vulnerability stems from unsafe use of ThinkPHP's update() method with field(true) enabled, which allows all POST/GET parameters to be mapped directly to database columns without whitelist filtering. Although the where clause restricts updates to the current user's record (id = $this->uid), an attacker can craft requests with arbitrary parameter names to modify sensitive fields like role, permissions, or admin flags. The attack requires authenticated access but can be executed remotely via HTTP. Upgrading to version 6.0.3 resolves this issue.
Affected products
- GouGuOA GouGuOA up to 5.10.0 and 6.0.1
Timeline
- 2026-09-02: disclosed: Vulnerability disclosed publicly
- 2026-08-22: patched: Version 6.0.3 released with fix