-
Notifications
You must be signed in to change notification settings - Fork 730
Pull requests: cool-team-official/cool-admin-midway
Author
Label
Projects
Milestones
Reviews
Assignee
Sort
Pull requests list
在
/src/modules/plugin/hooks/upload/index.ts 文件中发现存储型XSS漏洞。该漏洞源于在使用key定义文件名时完全没有对文件后缀进行校验,可能导致恶意用户上传包含脚本的文件,从而引发XSS攻击。
#231
opened Jan 12, 2026 by
dogdogcan
Loading…
ProTip!
Adding no:label will show everything without a label.