关键漏洞信息总结 Product Vendor Vendor Repository: !Product Vendor Repository Affected Product Code Repository Version: sz-boot-parent <= v1.3.2-beta Vulnerability Type Type: Arbitrary File Upload Vulnerability Description The API endpoint contains a critical arbitrary file upload vulnerability due to: Insufficient file type validation Insufficient filtering mechanisms in place This flaw allows unauthorized actors to upload arbitrary files, such as HTML, EXE, and other high-risk formats, to the target server without effective restrictions. Vulnerability Proof Request Example 1: Response Example 1: Request Example 2: Response Example 2: