Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| HumanSignal | label-studio | < 1.9.2post0 | - |
| # | POC Description | Source Link | Shenlong Link |
|---|---|---|---|
| 1 | An attacker can construct a filter chain to filter tasks based on sensitive fields for all user accounts on the platform by exploiting Django's Object Relational Mapper (ORM). Since the results of query can be manipulated by the ORM filter, an attacker can leak these sensitive fields character by character. | https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2023/CVE-2023-47117.yaml | POC Details |
No public POC found.
Login to generate AI POCNo comments yet