Worklenz 3.0.0 之前版本在解析基于任务的 API 端点时,未对任务所属组织进行有效校验,导致已认证用户可以访问其他租户的任务数据。攻击者可以通过使用任意任务 UUID 查询任务端点,从而获取其他组织的工作日志、评论、附件以及项目洞察信息。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet