CVE-2022-43140
EUVD-2022-4618617.11.2022, 17:15
kkFileView v4.1.0 was discovered to contain a Server-Side Request Forgery (SSRF) via the component cn.keking.web.controller.OnlinePreviewController#getCorsFile. This vulnerability allows attackers to force the application to make arbitrary requests via injection of crafted URLs into the url parameter.
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| keking | kkfileview | 4.1.0 |
𝑥
= Vulnerable software versions