GROWI 在 端点中存在一个访问控制漏洞。该端点在验证访问权限时,仅针对查询参数(query parameter)进行检查,但在返回由路径参数(path parameter)指定的修订版本内容时,并未确认这两个参数是否指向同一页面。因此,已认证的攻击者可以将其有权访问的页面标识符与任意的修订版本标识符进行组合,从而读取其本无权限查看的页面的修订版本内容。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet