Able to steal private files by manipulating response using Auto Reply function of Lark
High
L
Lark Technologies
Submitted None
Team Summary
Official summary from Lark Technologies
A IDOR (Insecure Direct Object Reference) vulnerability was found within the "AutoReply" functions of Lark. This vulnerability could have allowed malicious users to fetch the files of other users if they knew the specific file ID which was an alphanumeric value. We thank @imran_nisar for reporting this to our team and confirming its resolution.
Actions:
Reported by
imran_nisar
Report Details
Additional information and metadata
State
Closed
Substate
Resolved
Submitted
Weakness
Insecure Direct Object Reference (IDOR)