MOVO 0.2.3 及之前版本在 chat-api 文档端点中存在授权绕过漏洞,攻击者通过提供任意对象路径,可使已认证用户访问其他用户存储的对象。了解目标对象路径的攻击者可向 /api/documents/fetch 或 /api/documents/save-blueprint 发送请求,从而读取私有文档并覆盖演示蓝图(presentation blueprints)。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet