Any file upload vulnerability exists in the system
- Dominant language
- Java
- Stars
- 1.2k
- Forks
- 297
- PR merge metrics
- No merged PRs in 30d
Description
controller

service code

The problem code。Get the filename and extension from the front end

Contributor guide
No contributing guide indexed for this repository
Research direction
Start with the controller and service code shown in the attached images, then trace how the uploaded filename and extension reach the file-handling path. The issue names no files or tests, so identify the affected upload entry point and verify whether frontend-supplied metadata is trusted; done requires a confirmed finding and an agreed remediation path.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- java, spring-boot
- Domain
- backend, security
- Issue type
- Bug
- Difficulty
- 4/5
- Estimated time
- 3-5 days
- Activity status
- Stale
- Clarity
- Needs clarification
- Newbie friendliness
- 25/100