Loading HuntDB...

Removed user can still view comments on the file/documents.

Medium
L
Lark Technologies
Submitted None

Team Summary

Official summary from Lark Technologies

A vulnerability was found using a message API endpoint which could have resulted in a user being able to retrieve comments from a document after being removed. We thank @imran_nisar for reporting this to our team.

Reported by imran_nisar

Report Details

Additional information and metadata

State

Closed

Substate

Resolved

Submitted

Weakness

Improper Access Control - Generic