GROWI 在 端点中存在一个访问控制漏洞,该端点未能正确验证页面的访问权限。经过身份验证的攻击者可以通过提供已知的附件标识符,从他们无权查看的页面中获取附件元数据。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet