Twenty 2.35.0 之前的版本(含 2.35.0)中的 端点存在开放重定向漏洞,该端点将 查询参数直接当作重定向 URL 使用。攻击者可构造恶意请求,将用户重定向到任意主机,并在 禁用时绕过域名校验,从而转发 OAuth 授权码。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet