Open
Description
Contact Information
No response
MaxKB Version
1.10.8
Problem Description
put /api/function_lib/538cf118-4106-11f0-8885-0242ac140002
接口存在垂直越权问题。
Steps to Reproduce
1.使用函数库编辑函数,权限设为尽自己可见
2.模拟请求
3.切换一个账号(没有该函数的权限)
获取到authorization,把body的函数改成return2
结果:succeed
The expected correct result
No response
Related log output
Additional Information
No response