Yohane-Mashiro/dzzoffice_upload

Yohane-Mashiro/dzzoffice_upload

Releases0
Stars2
dzzoffice 文件上传导致xss

CVE History

CVEPublishedCVSS v3CVSS v2
9.8 CRITICAL

DzzOffice v2.3.7 and before is vulnerable to Arbitrary File Upload in /dzz/system/ueditor/php/controller.php.