在 Cal.com 版本 6.2.0 及更低版本中,发现了一个安全漏洞。该漏洞影响了组件 PBAC Permission Engine 中的 BookingAccessService.ts 文件下的 doesUserIdHaveAccessToBooking 函数。通过恶意操纵可导致权限缺失。攻击者可远程发起攻击。该漏洞的利用代码已公开,可能被用于实际攻击。目前,修复该问题的 Pull Request 已提交,等待审核接受。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet