IceCMS
IceCMS copied to clipboard
Arbitrary file upload
In the updateimage path of the imageApi file, the upload file type is not restricted, causing any file to be uploaded. At the same time, it is set to store the file locally if there is no remote bucket.
APIPath:IceWk-vues/src/api/updateImage.js updateImage Path: IceWk-ment/src/main/java/com/ttice/icewkment/controller/ImageApi.java