在 DocsGPT 0.20.0 及之前版本中,OAuth 连接器在回调状态(callback-status)端点处将会话令牌发送至通配符目标源,且未验证发送方来源。攻击者可以在 OAuth 授权过程中冒充 window.opener,从而获取会话令牌和提供商账户邮箱地址,并随后利用这些令牌断开受害者的云存储连接器。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet