'; } else{ echo ''; } echo '
|
|
|||
Release Date:2025/9/15
Rule Name:CVE-2022-43140:kkFileView v4.1.0 SSRF Vulnerability
Severity:critical
CVE ID:CVE-2022-43140
| Descripiton:
|
Keking kkFileView is a Spring Bot project developed by China's Keking Technology Co., Ltd. to create online preview files and documents. KkFileView v4.1.0 version has a security vulnerability, which originates from the component cn. keking. web. controller OnlinePreviewController # getCorsFile contains server-side request forgery (SSRF), which allows attackers to force applications to make arbitrary requests by injecting crafted URLs into URL parameters.This rule supports to defend the A6: Vulnerable and Outdated Components of OWASP Top 10 - 2021.
Other reference:None
| Solution:
|
Update vendor patches.