Art of Problem Solving security flaw! (fixed)
In the AoPS classroom (https://artofproblemsolving.com/classroom/room/XXX), when a user joins a room, the server fires a “room-joined” event to the client. The event data contains all the users, but the user session id is also sent. This session id is, in fact, the same as the session id stored in the “aopssid” cookie. Then, if a … Read more