目标: 1000 元 · 已筹: 1359 元
The application does not verify whether the attacker is the creator of the file, allowing the attacker to directly call the GET /api/chat/file/{file_id} interface to view any user's file.
登录后查看神龙缓存的 POC 文件快照