AppFlowy-Cloud 0.9.64 版本在授权检查中未能验证所请求的协同对象是否属于当前工作区,导致攻击者能够跨工作区访问文档和数据库记录。攻击者可以通过提供受害者的对象 ID 并搭配自己的工作区 ID,从而绕过访问控制,实现对跨工作区数据的读取、修改或删除。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| AppFlowy-IO | AppFlowy-Cloud | ≤ 0.9.64 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| AppFlowy-IO | AppFlowy-Cloud | 0 ~ 0.9.64 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet