Impact
kkFileView versions 4.2.0 and later allow a server‐side request forgery when an attacker supplies both an innocuous "url" parameter that passes the TrustHostFilter and a malicious "urlPath" parameter that the controller actually uses. The filtered value is never used, so the application fetches the requested internal resource and returns its content to the attacker. This flaw can expose sensitive data, network services, or configuration files from the host on which kkFileView runs.
Affected Systems
The vulnerability is present in all installations of kkFileView starting at version 4.2.0. Users deploying any version 4.2.0 or newer must verify whether remediation patches have been applied and whether the getCorsFile endpoint is exposed.
Risk and Exploitability
The CVSS score of 9.1 indicates a critical condition with high impact and ease of exploitation. The EPSS score of less than 1% suggests that active exploitation is currently sparse, and the vulnerability is not listed in the CISA KEV catalog. Nevertheless, because the flaw enables arbitrary internal requests, attackers can potentially enumerate or exfiltrate internal data with minimal effort. The viable attack path requires only the ability to send an HTTP request to the vulnerable endpoint, making it suitable for remote attackers with no user interaction besides URL manipulation.
OpenCVE Enrichment