CyberRota Analysis
AI-GeneratedSiYuan versions prior to 3.8.5 are vulnerable to an information disclosure flaw that enables unauthorized users to access sensitive data from password-protected and publish-disabled database rows through the /api/export/preview endpoint. This vulnerability allows attackers to extract primary-key text and cell values from protected rows by requesting an export preview of a public document. Organizations using affected versions should prioritize patching to mitigate the risk of data exposure.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
SiYuan before 3.8.5 contains an information disclosure vulnerability that allows publish readers to read password-protected and publish-disabled database rows via the /api/export/preview endpoint. Attackers can request an export preview of a public document embedding a database view to obtain protected rows' primary-key text and cell values.