kkFileView 4.0 contains a server-side request forgery caused by improper validation in OnlinePreviewController.java, letting attackers induce the server to make arbitrary requests, exploit requires sending crafted requests.
id: CVE-2022-42149
info:
name: kkFileView 4.0 - Server-Side Request Forgery
author: Arm!tage
...