[AWC-Pune] - User can download files deleted by Admin using shortcuts
Medium
L
Lark Technologies
Submitted None
Team Summary
Official summary from Lark Technologies
A vulnerability was found in where a Lark user could bypass Admin restrictions on deleted files, which typically would block users of the file from downloading or using it. However, the user could add a shortcut of the file to a folder, and upon downloading that folder could access the file previously deleted by the Admin. We thank @prateek_thakare for reporting this to our team and confirming its resolution.
Actions:
Reported by
prateek_thakare
Report Details
Additional information and metadata
State
Closed
Substate
Resolved