APITable 1.13.0-beta.1 之前的版本未对内部的组织加载/搜索端点( )进行身份验证,使得未认证的攻击者能够获取成员姓名、电子邮件地址以及团队层级结构。攻击者可以利用从共享链接或公开模板中获取的工作空间标识符查询该端点,从而枚举任意工作空间的完整成员目录。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet