Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

官网下载的版本中有个插件存在重大安全漏洞 lib/webuploader #14

Open
yangfancn opened this issue Dec 3, 2021 · 6 comments

Comments

@yangfancn
Copy link

文件位置 : /lib/webuploader/0.1.5/server/preview.php
image
没有做任何文件后缀限制,可被直接上传php文件等
我几十个网站因此被上传后门文件,首页被篡改,跳到博彩网站

@Charles94jp
Copy link

我去,这原生前端模板里还有php文件?😂 那我用Java吧

@herbert-wu
Copy link

herbert-wu commented Dec 29, 2021 via email

@jackying
Copy link
Owner

ueditor、webuploader 这两个组件中php文件是上传的服务端demo,是让写服务端的人参考用的,可以完全删除掉。很多人不会写服务端的上传,所以插件中带了demo代码,记着要删除。

@herbert-wu
Copy link

herbert-wu commented Feb 21, 2022 via email

@MushuScript
Copy link

插眼

@herbert-wu
Copy link

herbert-wu commented Nov 13, 2022 via email

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

5 participants