Beveiligingsadvies

CVE-2022-43140

CVE-kwetsbaarheidsdetails - eXtreme Datacenter Security Operations

Gepubliceerd 2022-11-17 00:00:00
Laatst bijgewerkt 2025-04-30 14:07:01
Toegewezen door mitre
CVSS-score 7.5
Status PUBLISHED

Beschrijving

kkFileView v4.1.0 was discovered to contain a Server-Side Request Forgery (SSRF) via the component cn.keking.web.controller.OnlinePreviewController#getCorsFile. This vulnerability allows attackers to force the application to make arbitrary requests via injection of crafted URLs into the url parameter.