中的 过程仅接受 参数,并直接返回 的结果。 中的 中间件仅在输入包含 或 键时才会进行成员资格验证;因此,仅包含 的输入未经验证即被放行。随后, 中的 函数仅根据 执行 查询,未对项目范围进行限制。因此,任何经过身份验证的用户都可以通过提供报告标识符,读取实例上任意已保存报告的完整配置信息,包括所属项目的 、事件系列(event series)、过滤器(filters)、分面(breakdowns)以及公式(formulas)。相比之下,相邻的 、 和 过程会先解析报告,并针对报告自身的 调用 进行访问权限检查。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Openpanel-dev | openpanel | < 0a51b6805eed0b3da8376175acd5fa3d26819cb6 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Openpanel-dev | openpanel | 0 ~ 0a51b6805eed0b3da8376175acd5fa3d26819cb6 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet