CyberRota Analysis
AI-GeneratedAppFlowy-Cloud versions 0.7.2 through 0.9.64 are vulnerable due to inadequate authorization checks in the bulk publish endpoint, enabling authenticated users to publish content in other tenants' namespaces. This flaw allows attackers to manipulate published views, potentially defacing public pages or deploying phishing content under trusted URLs. Organizations using affected versions should prioritize remediation to prevent unauthorized content manipulation and protect their users from phishing attacks.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
AppFlowy-Cloud versions 0.7.2 through 0.9.64 fail to authorize callers against the workspace in the bulk publish endpoint path, allowing authenticated users to publish content into other tenants' namespaces. Attackers can write published views with attacker-controlled title, body and metadata into victim workspaces to deface public pages or host phishing content on trusted URLs.