← Zurück zur CVE-Suche

CVE-2026-72806

SiYuan

Beschreibung

SiYuan versions before v3.7.4 contain an authentication bypass vulnerability in the FilterViewByPublishAccess filter that fails to check publish password protection when rendering attribute views and database rows. Unauthenticated readers can access password-protected document rows including titles, block IDs, and column values by calling renderAttributeView without supplying the required password.

CVSS 5.8EPSS 0.307%Risiko 0.6
Quelle öffnen
Veröffentlicht
2026-08-12 20:17:52
Betroffene Versionen
<3.7.4
Typ
Webanwendung
Zuletzt geändert
2026-08-26 16:56:50
Vektor
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:N/A:N