AppFlowy-Cloud 0.7.2 至 0.9.64 版本在“批量发布”(bulk publish)端点的路径处理中,未能正确验证调用者与目标工作区(workspace)的授权关系。这使得已认证用户能够将内容发布到其他租户(tenant)的命名空间中。攻击者可以利用这一缺陷,在受害者的工作区中写入由攻击者控制的标题、正文和元数据所构成的已发布视图,从而篡改公开页面内容,或在受信任的 URL 上托管钓鱼内容。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| AppFlowy-IO | AppFlowy-Cloud | 0.7.2 ~ 0.9.64 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet