dromara / dromara/skyeye

Any file upload vulnerability exists in the system

Open
#10 3 comments 0 reactions 0 assignees View on GitHub
Dominant language
Java
Stars
1.2k
Forks
297
PR merge metrics
No merged PRs in 30d

Description

controller
![image](https://user-images.githubusercontent.com/43632720/161500272-74a7df88-736d-4439-84c7-f599b9495070.png)
service code
![image](https://user-images.githubusercontent.com/43632720/161500337-cfebe76a-ecce-4fb4-9e7f-3adb1bf7ea3b.png)
The problem code。Get the filename and extension from the front end
![image](https://user-images.githubusercontent.com/43632720/161500451-9fc8debf-fa4d-4215-8f90-356be0e4773b.png)

Contributor guide

No contributing guide indexed for this repository

Research direction

Start with the controller and service code shown in the attached images, then trace how the uploaded filename and extension reach the file-handling path. The issue names no files or tests, so identify the affected upload entry point and verify whether frontend-supplied metadata is trusted; done requires a confirmed finding and an agreed remediation path.

Written by the indexing model from the issue text.

Assessment

Tech stack
java, spring-boot
Domain
backend, security
Issue type
Bug
Difficulty
4/5
Estimated time
3-5 days
Activity status
Stale
Clarity
Needs clarification
Newbie friendliness
25/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.