Open Source Social Network(OSSN)10.1 及以下版本在 文件中存在不安全的直接对象引用(IDOR)漏洞。该漏洞允许已认证用户读取其他用户的私有消息附件。攻击者可以通过顺序遍历或猜测文件的全局唯一标识符(GUID),向 路由发起请求,从而在无需验证发送方或接收方身份的情况下,获取私有对话中的附件。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| opensource-socialnetwork | opensource-socialnetwork | ≤ 10.1 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| opensource-socialnetwork | opensource-socialnetwork | 0 ~ 10.1 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet