First published: Thu Nov 17 2022(Updated: )
kkFileView v4.1.0 was discovered to contain a Server-Side Request Forgery (SSRF) via the component cn.keking.web.controller.OnlinePreviewController#getCorsFile. This vulnerability allows attackers to force the application to make arbitrary requests via injection of crafted URLs into the url parameter.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
kkFileView | =4.1.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-43140 is a vulnerability in kkFileView v4.1.0 that allows Server-Side Request Forgery (SSRF) attacks.
CVE-2022-43140 has a severity rating of 7.5, which is considered high.
CVE-2022-43140 allows attackers to inject crafted URLs into the url parameter of cn.keking.web.controller.OnlinePreviewController#getCorsFile, enabling them to force the application to make arbitrary requests.
CVE-2022-43140 affects kkFileView v4.1.0.
At the time of writing, there is no known fix for CVE-2022-43140. It is recommended to follow the official advisory and monitor for updates from the vendor.