S4E just found a high-severity finding from cve-2026-42945 scanner (version based)
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
medium·Product Based Web Vulnerabilities·Updated Jan 3, 2024

CVE-2022-35151 Scanner

CVE-2022-35151 scanner - Cross-Site Scripting (XSS) vulnerability in kkFileView

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, ipv4, subdomain
CostFree
2.1k
Times Used
continuous scan runs
4.7k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2022-35151
6.1
CVSS

kkFileView v4.1.0 was discovered to contain multiple cross-site scripting (XSS) vulnerabilities via the urls and currentUrl parameters at /controller/OnlinePreviewController.java.

Attack Vector
-
Privileges Req.
-
User Interaction
-
Affected
n/aby n/a
n/a
Updated Aug 22, 2026View on NVD →
Detail

kkFileView is a software program that allows users to view multiple file formats on their computer. It is designed to be a versatile viewer that can handle a wide range of file types, including images, videos, documents, and audio files. With its user-friendly interface and intuitive navigation, kkFileView is a popular choice for individuals and businesses alike who want a tool that can easily display various file formats without the need for specialized software.

The CVE-2022-35151 vulnerability discovered in kkFileView v4.1.0 is a critical cross-site scripting (XSS) flaw that could allow an attacker to inject malicious code into a targeted website or web application. Specifically, the vulnerability is present in the urls and currentUrl parameters of the controller/OnlinePreviewController.java file, which are used to generate web pages containing preview files. By exploiting this vulnerability, an attacker could potentially gain unauthorized access to sensitive information, damage the system, or launch a variety of other attacks.

When exploited, the CVE-2022-35151 vulnerability in kkFileView can result in severe consequences for affected users. For starters, it can allow an attacker to gain access to sensitive information, such as login credentials, personal information, and financial data. Additionally, it can lead to the hijacking of web sessions, which could result in the manipulation of data or the injection of malware onto the system. Finally, this vulnerability can also be used as a launching point for other attacks on the system, including cross-site request forgery (CSRF) and denial-of-service (DoS) attacks.

In conclusion, security is an important consideration for anyone using digital assets. Thanks to the pro features of the s4e.io platform, it is now possible for individuals and businesses to quickly and easily learn about vulnerabilities in their systems and take the necessary precautions to protect against them. By staying up-to-date on the latest security trends and best practices, users can keep their digital assets safe from attacks and ensure that their personal and sensitive information remains secure.

 

REFERENCES

Solution Advice

In order to protect against the CVE-2022-35151 vulnerability in kkFileView, users are advised to take the following precautions:

  • Update to the latest version of kkFileView as soon as a patch becomes available
  • Disable the Online Preview feature in kkFileView if it is not necessary
  • Avoid clicking on suspicious links or visiting unknown websites
  • Use a reputable antivirus program to detect and prevent XSS attacks
  • Regularly scan your system for vulnerabilities using a comprehensive vulnerability scanner tool

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.