Loading HuntDB...

Able to steal private files by manipulating response using Compose Email function of Lark

High
L
Lark Technologies
Submitted None

Team Summary

Official summary from Lark Technologies

A IDOR (Insecure Direct Object Reference) vulnerability was found within the "Compose Email" functions of Lark. This vulnerability could have allowed malicious users to fetch the files of other users if they knew the specific file ID which was an alphanumeric value. We thank @imran_nisar for reporting this to our team and confirming its resolution.

Reported by imran_nisar

Report Details

Additional information and metadata

State

Closed

Substate

Resolved

Submitted

Weakness

Insecure Direct Object Reference (IDOR)