Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
SiYuan before v3.7.3 Authentication Bypass via Content Endpoints
Vulnerability Description
SiYuan versions before v3.7.3 contain an authentication bypass vulnerability in publish mode where content-returning endpoints getHeadingChildrenDOM, getHeading*Transaction, and getBacklinkDoc perform no password check despite protecting the primary getDoc endpoint. Anonymous attackers can retrieve full content of password-protected documents by obtaining internal block IDs from reader-accessible endpoints and calling unprotected content endpoints to bypass the password gate.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N
Vulnerability Type
使用候选路径或通道进行的认证绕过
Vulnerability Title
SiYuan 授权问题漏洞
Vulnerability Description
SiYuan是SiYuan团队开源的一款文档管理软件。 SiYuan 3.7.3之前版本存在授权问题漏洞,该漏洞源于发布模式下内容返回端点getHeadingChildrenDOM、getHeading*Transaction和getBacklinkDoc未执行密码检查,可能导致匿名攻击者获取内部块ID并调用未受保护端点绕过密码验证,获取受密码保护文档的完整内容。
CVSS Information
N/A
Vulnerability Type
N/A