Loading HuntDB...

[AWC-Pune] - User can download files deleted by Admin using shortcuts

Medium
L
Lark Technologies
Submitted None

Team Summary

Official summary from Lark Technologies

A vulnerability was found in where a Lark user could bypass Admin restrictions on deleted files, which typically would block users of the file from downloading or using it. However, the user could add a shortcut of the file to a folder, and upon downloading that folder could access the file previously deleted by the Admin. We thank @prateek_thakare for reporting this to our team and confirming its resolution.

Reported by prateek_thakare

Report Details

Additional information and metadata

State

Closed

Substate

Resolved

Submitted