kekingcn kkFileView是kekingcn组织的一款文件预览中间件。 kekingcn kkFileView 5.0.1之前版本存在服务端请求伪造漏洞,该漏洞源于/addTask端点未经过TrustHostFilter和TrustDirFilter过滤,且FileHandlerService#getFileAttribute使用fullfilename参数强制类型,导致可获取攻击者选择的URL,容易受到服务端请求伪造攻击。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| kekingcn | kkFileView | < 5.0.1 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| kekingcn | kkFileView | < 5.0.1 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
VULNERABLE: SSRF via unauthenticated /addTask — kkFileView (kv) fetched http://attacker:8080/flag.txt; served file carries PROOF_2506e3b249844b2b
No comments yet