Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

a security risk #175

Open
pengshuo123 opened this issue Dec 8, 2023 · 0 comments
Open

a security risk #175

pengshuo123 opened this issue Dec 8, 2023 · 0 comments

Comments

@pengshuo123
Copy link

Until now,For all versions, there are security risks in the add_link method in the class/Api.php file. As shown in the figure, when we set the url to the intranet IP, we can also access the title, introduction and other information of the web website, which will be in the link name. After obtaining the title of the web service,
daaa75cff8552e458b6c06e17960ab7d
if other services are enabled, such as the Elastic monitoring service, you can also add ports to see if other web services are enabled and detect intranet web service information.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant