by-night/sms

by-night/sms

Releases0
Stars414
基于vue + springboot的学生成绩管理系统

CVE History

CVEPublishedCVSS v3CVSS v2
8.8 HIGH

by-night sms V1.0 has an Arbitrary File Upload vulnerability. The /api/sms/upload/headImg endpoint allows uploading arbitrary files. Users can upload files of any size and type.