CyberRota Analysis
AI-GeneratedAPITable versions up to 1.13.0-beta.1 are vulnerable due to an unauthenticated exposure of the internal loadOrSearch endpoint, enabling attackers to access sensitive information such as member names, email addresses, and team hierarchy. This vulnerability allows for the enumeration of the complete member directory of any workspace using space identifiers from shared links or public templates. Organizations utilizing APITable should prioritize remediation to protect their user data and prevent unauthorized access.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
APITable through 1.13.0-beta.1 exposes the internal organization loadOrSearch endpoint without authentication, allowing unauthenticated attackers to retrieve member names, email addresses, and team hierarchy. Attackers can query the endpoint with space identifiers obtained from shared links or public templates to enumerate the complete member directory of any workspace.