lizhipay / acg-faka

个人发卡源码,发卡系统,二次元发卡系统,二次元发卡源码,发卡程序,动漫发卡,PHP发卡源码,异次元发卡
MIT License
3.5k stars 690 forks source link

acg-faka Background can delete any file #31

Closed eexp closed 1 year ago

eexp commented 1 year ago

Vulnerability location app/Controller/Admin/Api/App.php uninstall() image The system does not verify the post value so we can input anything Delet chain image image but it has waf we can use url encode bypass it pyload image we send the post the we can see All files in this directory have been deleted image

lizhipay commented 1 year ago

It doesn't help.