在 eladmin 项目的 commit 55fbf70 中,downloadS3Storage 处理器存在缺失授权验证的漏洞,允许任何已认证的用户在无需存储权限的情况下获取已存储对象的 URL。攻击者可以通过对 GET /api/s3Storage/download/{id} 接口进行连续 ID 枚举,收集所有已上传对象的 URL,从而暴露在公共可读存储桶中的文件内容。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet