TIM Flow 26.0.6 版本之前存在不正确的授权漏洞,该漏洞允许任何已认证用户向仅限管理员使用的仪表板 Excel 导出端点提交任意 SQL 查询。攻击者可以构造并发送未授权的 SQL 查询到导出端点,以可下载的电子表格形式获取敏感数据库内容,从而绕过基于角色的访问控制。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| TIM Solutions | TIM Flow | < 26.0.6 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| TIM Solutions | TIM Flow | 0 ~ 26.0.6 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet