kkFileView
kkFileView copied to clipboard
XSS Vulnerability
In AttributeSetFilter, multiple parameters are not XSS filtered
cn.keking.web.filter.AttributeSetFilter#setWatermarkAttribute
Parameters are used in commonHeader
src/main/resources/web/commonHeader.ftl
The modified template is referenced by multiple template files, among which picture.ftl
This template is used in /picturesPreview
cn.keking.web.controller.OnlinePreviewController#picturesPreview
Vulnerability recurrence
/picturesPreview
?urls=aHR0cDovLzE=
&watermarkXSpace=1});}}alert(1);function a(){function b(){return ({//