kkFileView
kkFileView copied to clipboard
Cross site scripting vulnerability
Unauthorized API: @ GetMapping ("/picturesPreview") does not conduct XSS (Cross Site Scripting) defense on the parameter currentUrl, resulting in a cross site scripting attack vulnerability
cn.keking.web.controller.OnlinePreviewController#picturesPreview
src/main/resources/web/picture.ftl
Attack
currentUrl=http://");alert(1);//
http://127.0.0.1:8012/picturesPreview?urls=¤tUrl=aHR0cDovLyIpO2FsZXJ0KDEpOy8v