在 2.35.0 之前的 Twenty 版本中, 与 组合的 GraphQL 解析器未正确验证字段和行的权限,使得经过身份验证的用户能够绕过权限检查。拥有 权限但 为 的攻击者,可以通过 解析器获取原本应被拒绝的受限字段值。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet