EspoCRM 在 10.0.4 版本之前存在一个字段级权限绕过漏洞,位于会议和通话参会者接口中,该漏洞允许已认证的用户读取受限的电子邮件地址。攻击者可通过利用不正确的 ACL 作用域验证逻辑来恢复被隐藏的参会者邮箱——该验证错误地检查了父级活动(事件)的权限,而未针对参会者实体本身进行权限校验。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet