OSV 1.4.0 · unreviewed · 修改于 2026-08-28 02:32
发布时间
2026-08-27 08:30
GitHub 审查时间
—
NVD 发布时间
2026-08-27 06:16
源文件
advisories/unreviewed/2026/08/GHSA-g8c8-m4x5-p2mp/GHSA-g8c8-m4x5-p2mp.json
tamguo 1.5.3 is vulnerable to Unrestricted File Upload Leading to Stored XSS. The /uploadFile and /imgUpload endpoints in FileUploadController.java and UEditorController.java have no file type validation. Attackers can upload arbitrary HTML/JavaScript files to the server.
该公告没有提供结构化的受影响软件包信息。