Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
SiYuan before v3.7.3 Content Disclosure via getBacklinkDoc
Vulnerability Description
SiYuan before v3.7.3 fails to apply publish-access filters to the getBacklinkDoc and getBackmentionDoc content endpoints (/api/ref/getBacklinkDoc and /api/ref/getBackmentionDoc). While the corresponding backlink list endpoints filter publish-forbidden documents, the content endpoints (gated only by CheckAuth) do not. A publish-mode reader — including an anonymous reader when publish Basic Auth is disabled — can call these endpoints directly with a publish-forbidden document's ID to retrieve its rendered DOM content and to determine whether the document references a given block (a reference-existence oracle).
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N
Vulnerability Type
授权机制缺失
Vulnerability Title
SiYuan 授权问题漏洞
Vulnerability Description
SiYuan是SiYuan团队开源的一款文档管理软件。 SiYuan 3.7.3之前版本存在授权问题漏洞,该漏洞源于未对getBacklinkDoc和getBackmentionDoc内容端点(/api/ref/getBacklinkDoc和/api/ref/getBackmentionDoc)应用发布访问过滤器,可能导致发布模式读者(包括匿名读者)直接调用这些端点,检索被禁止发布文档的渲染DOM内容,并判断文档是否引用给定块。
CVSS Information
N/A
Vulnerability Type
N/A