File upload interface 漏洞列表
共找到 1 个与 File upload interface 相关的漏洞
📅 加载漏洞趋势中...
-
CVE-2023-28435: File upload interface does not do permission verification exists XSS vulnerability POC
The file upload interface is not checked for permissions, so users who are not logged in can upload any file directly to the background, and the file type is not checked, so they can upload any type of file ps:上传文件后,通过路径/static-resource/{{ranfilename}}.html触发xss