Skip to content

SS.Form表单插件 漏洞 泄密 问题反馈  #18

@dingduv

Description

@dingduv

表单提交可获取表单的信息,如下:
/SiteFiles/Plugins/SS.Form/templates/submit1/index.html?siteId=1&formId=1&apiUrl=%2fapi

现在无需登陆管理后台,只需要输入域名/api/ss.form/1/1即可获取已提交的数据信息。其中前面数字1对应siteId,后面的1对应formId。

捕获
捕获1

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type
    No fields configured for issues without a type.

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions