A multi-tenant social media monitoring and PR SaaS platform exposed customer documents across organizations through a path traversal flaw in its file download workflow. Researchers found that an authenticated user could manipulate the folderPath parameter in the /api/clientpublicdoc endpoint, causing the public API to rewrite an internal request to the platform’s document management service and return data from other tenants’ asset-library directories. The weakness effectively became a Broken Object Level Authorization issue by allowing access to objects belonging to other customers without proper authorization checks.
The researchers reported that tenant directory names could be derived from the sourceKey field returned by /api/clientpublicdoc/list, and those names were predictable because they embedded sequential client IDs. By substituting another tenant’s sourceKey, an attacker could enumerate files belonging to other organizations and obtain direct CDN publicUrl links that required no authentication, exposing filenames, metadata, marketing assets, brochures, and internal documents. The case highlights how path traversal in APIs can extend beyond filesystem access and directly undermine tenant boundary enforcement in shared SaaS environments.

See affected versions and whether adversaries are exploiting it.
1 event from the most recent confirmed update back to the earliest known activity.
Cognisys Group Labs published research describing a vulnerability in a multi-tenant social media monitoring and PR platform where manipulating the folderPath parameter in /api/clientpublicdoc let an authenticated tenant enumerate and access other tenants’ Asset Library contents via an internal DMS API. The write-up states the issue exposed filenames, metadata, and direct CDN download links for other organizations’ files, breaking tenant isolation.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
3 references tracked. Mallory keeps watching after this page renders.
labs.cognisys.group
Open sourceportswigger.net
Open sourceowasp.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.