We read every piece of feedback, and take your input very seriously.
To see all available qualifiers, see our documentation.
Have a question about this project? # for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “#”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? # to your account
描述您遇到的bug webcute v3.2.2 在這些page上存在CSV injection [Home / Admin / Resources] page [Home / Admin / System Params] page [Home / Design / Basekey Configuration] page
如何重现 input =10+20+cmd|' /C calc'!A0 並export csv出來,在使用windows系統開啟
=10+20+cmd|' /C calc'!A0
预期行为 跳出程式calc.exe
截图
附加
The text was updated successfully, but these errors were encountered:
No branches or pull requests
描述您遇到的bug
webcute v3.2.2
在這些page上存在CSV injection
[Home / Admin / Resources] page
[Home / Admin / System Params] page
[Home / Design / Basekey Configuration] page
如何重现
input
=10+20+cmd|' /C calc'!A0
並export csv出來,在使用windows系統開啟
预期行为
跳出程式calc.exe
截图
![01](https://user-images.githubusercontent.com/43329333/183076721-86732770-a933-4147-a511-9466f5ead551.png)
![02](https://user-images.githubusercontent.com/43329333/183076745-85790cbb-3b6b-4b4a-8b82-c49bf4ff222b.png)
附加
The text was updated successfully, but these errors were encountered: