在 DataEase 2.10.26 之前的版本中,地理信息、仪表盘联动以及图表详情等 REST 接口缺失了对象级的权限校验,这使得经过身份验证的用户能够访问属于其他用户的资源。攻击者可以通过在请求中提供任意标识符,覆盖或删除地图几何图形、修改仪表盘联动设置,并获取其并不拥有的资源的图表元数据及配置。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet