在 SiYuan v3.8.4 之前的版本中, 端点未能正确实施发布访问检查,导致发布读者可以从未授权数据库中检索图像资产路径。攻击者可以通过相关端点获取未渲染的数据库标识符,并调用该端点,从而泄露由渲染端点本应拒绝的独立行图像资产路径和文件名。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| siyuan-note | siyuan | 0 ~ 3.8.4 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet