Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

安全性问题 #15

Open
Gyxqq opened this issue Nov 27, 2023 · 4 comments
Open

安全性问题 #15

Gyxqq opened this issue Nov 27, 2023 · 4 comments

Comments

@Gyxqq
Copy link

Gyxqq commented Nov 27, 2023

可以通过http://192.168.3.2/#/123/../.. 这样的方式访问到根目录的上层文件夹,相当于将系统文件全部暴露,只是无法下载,但是仍可查看目录文件名等信息

@Tsin09
Copy link

Tsin09 commented Dec 24, 2023

可以解决一下吗?

@feipinxiang
Copy link

3.1版本也可以通过 #/../ 访问上级目录

@Hugengrui
Copy link

权限设定为"::|admin:admin:rwd"后,匿名访问仍不受限制。

@Hugengrui
Copy link

目前可行的解决办法是回退旧版本

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

4 participants