bihell / Dice

一个前端后端分离的个人内容管理(CMS)系统。包含权限、博客、导航等模块。采用Nuxt、Vue2/3和SpringBoot3框架开发。
MIT License
474 stars 131 forks source link

any file upload vuln #157

Closed lanfei-4 closed 1 year ago

lanfei-4 commented 2 years ago

1、Any file upload vulnerability in the following code can cause RCE image 2、Follow up the code、Files are directly uploaded to the server without filtering image

bihell commented 1 year ago

项目已重构,这块晚点有时间弄