S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
high·Product Based Web Vulnerabilities·Updated Mar 5, 2024

CVE-2022-43140 Scanner

CVE-2022-43140 scanner - Server-Side Request Forgery (SSRF) vulnerability in kkFileView

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsurl
CostFree
2.2k
Times Used
continuous scan runs
5.5k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2022-43140
7.5
CVSShigh
Exploitable remotely over the internet · no authentication required.

kkFileView v4.1.0 was discovered to contain a Server-Side Request Forgery (SSRF) via the component cn.keking.web.controller.OnlinePreviewController#getCorsFile. This vulnerability allows attackers to force the application to make arbitrary requests via injection of crafted URLs into the url parameter.

Attack Vector
Network
Privileges Req.
None
User Interaction
None
Affected
n/aby n/a
n/a
Updated Aug 22, 2026View on NVD →
Detail

kkFileView is a versatile file preview and conversion tool designed for integration with web applications. It supports a wide range of file formats, allowing users to view documents, images, and videos directly in their web browser without needing to download or open them in external applications. The software is particularly useful for content management systems, document sharing platforms, and collaborative environments where quick and easy access to various file types is essential. Developed by Keking, kkFileView is popular among developers and organizations looking to enhance their web applications with rich document viewing capabilities.

In version 4.1.0 of kkFileView, a critical Server-Side Request Forgery (SSRF) vulnerability exists. This flaw allows attackers to send crafted requests from the server to internal or external resources. Exploiting this vulnerability, attackers can bypass security mechanisms to access restricted internal services, conduct port scanning, and potentially access sensitive information. The vulnerability stems from inadequate validation of user-supplied URLs, specifically within the OnlinePreviewController#getCorsFile component, where an attacker can manipulate the URL parameter to initiate unauthorized requests.

The SSRF vulnerability in kkFileView 4.1.0 arises from the application's handling of the `urlPath` parameter in the `getCorsFile` method. By encoding a malicious URL in Base64 and passing it as the `urlPath` parameter, an attacker can coerce the server into making arbitrary HTTP requests to internal or external resources. This behavior can be exploited to interact with services that are only accessible from the server's internal network, leading to information disclosure, internal network mapping, or further exploitation of internal vulnerabilities.

The potential impacts of exploiting this SSRF vulnerability include unauthorized access to internal network services, data exfiltration, and leveraging the server's trust relationship to conduct further attacks. Additionally, this vulnerability could be used as a stepping stone for more severe attacks, such as remote code execution, depending on the configuration and security measures in place on the internal network.

Joining S4E provides access to cutting-edge vulnerability scanning and cybersecurity management tools. By leveraging our platform, you can quickly identify and mitigate vulnerabilities like SSRF in kkFileView, enhancing the security posture of your web applications. Our service offers detailed reports, prioritized remediation guidance, and continuous monitoring, ensuring that your digital assets are protected against the latest security threats.

 

References

Solution Advice
  1. Upgrade kkFileView to the latest version that addresses this SSRF vulnerability.
  2. Implement strict input validation and sanitization to ensure that only valid URLs are processed.
  3. Employ network segmentation and firewall rules to restrict outbound requests from servers hosting web applications.
  4. Regularly audit and monitor outbound requests to detect and respond to potential SSRF attempts.
  5. Consider using security tools that specifically detect and prevent SSRF attacks as part of your application's security measures.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.