atjiu / pybbs

更实用的Java开发的社区(论坛),Better use of Java development community (forum)
GNU Affero General Public License v3.0
1.84k stars 706 forks source link

Vulnerability Alert #191

Closed cxcxcxcxcxcxcxc closed 1 month ago

cxcxcxcxcxcxcxc commented 2 months ago

The username is controllable and has no filtering, allowing for directory traversal.

image

atjiu commented 1 month ago

在IndexApiController的100行做了验证

https://github.com/atjiu/pybbs/blob/714b1bbc17938de0bef1bb3320868ba0457a422f/src/main/java/co/yiiu/pybbs/controller/api/IndexApiController.java#L100