GROWI 的附件请求权限检查仅在请求携带已认证用户时才执行。 函数(位于 )通过一个要求用户对象非空的条件来守卫该权限检查,因此,未携带会话信息的请求将完全绕过此检查,处理器直接返回文件。 通过 和 这两个路由可到达上述逻辑,它们从 URL 路径中获取附件标识符。因此,拥有附件标识符的未认证调用者无论该附件所属页面是否为私有,也无论其是否被允许查看该页面,均可直接获取该文件。标识符可能被后续访问权限被移除的用户保留,或从此前暴露过该标识符的任何位置恢复获取。 在版本 8.0.2 中,系统对已认证和未认证的请求均执
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| GROWI, Inc. | GROWI | < 8.0.2 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| GROWI, Inc. | GROWI | 0 ~ 8.0.2 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No comments yet