kkFileView v4.1.0 was discovered to... CVE-2022-43140

- AV AC AU C I A
发布: 2024-12-11
修订: 2024-12-11

kkFileView v4.1.0 was discovered to contain a Server-Side Request Forgery (SSRF) via the component cn.keking.web.controller.OnlinePreviewController#getCorsFile. This vulnerability allows attackers to force the application to make arbitrary requests via injection of crafted URLs into the url parameter.

0%
暂无可用Exp或PoC
当前有0条受影响产品信息