Loading HuntDB...

Messages disclosure via search feature of other users group(Cross-Tenant).

Medium
L
Lark Technologies
Submitted None

Team Summary

Official summary from Lark Technologies

Due to a Insecure Direct Object Reference (IDOR) vulnerability identified within the message search function of Lark, an attacker could have potentially viewed messages, docs, and attachments shared in other users groups. We thank @base_64 for reporting this to our team and verifying the resolution.

Reported by base_64

Report Details

Additional information and metadata

State

Closed

Substate

Resolved

Submitted

Weakness

Insecure Direct Object Reference (IDOR)