CyberRota Analysis
AI-GeneratedVersions of SiYuan prior to v3.7.4 are vulnerable to an authentication bypass in the FilterViewByPublishAccess filter, allowing unauthenticated users to access sensitive information from password-protected document rows. This vulnerability could lead to unauthorized disclosure of titles, block IDs, and column values. Organizations using affected versions should prioritize patching to mitigate potential data exposure risks.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
SiYuan versions before v3.7.4 contain an authentication bypass vulnerability in the FilterViewByPublishAccess filter that fails to check publish password protection when rendering attribute views and database rows. Unauthenticated readers can access password-protected document rows including titles, block IDs, and column values by calling renderAttributeView without supplying the required password.