Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-23r8-p7qp-rwcq

Опубликовано: 14 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 8.1

Описание

A Server-Side Request Forgery (SSRF) vulnerability exists in MicroStrategy Web SDK 11.1 and earlier, allows remote unauthenticated attackers to conduct a server-side request forgery (SSRF) attack via the srcURL parameter to the shortURL task.

A Server-Side Request Forgery (SSRF) vulnerability exists in MicroStrategy Web SDK 11.1 and earlier, allows remote unauthenticated attackers to conduct a server-side request forgery (SSRF) attack via the srcURL parameter to the shortURL task.

EPSS

Процентиль: 83%
0.0195
Низкий

8.1 High

CVSS3

Дефекты

CWE-918

Связанные уязвимости

CVSS3: 8.1
nvd
около 3 лет назад

A Server-Side Request Forgery (SSRF) vulnerability exists in MicroStrategy Web SDK 11.1 and earlier, allows remote unauthenticated attackers to conduct a server-side request forgery (SSRF) attack via the srcURL parameter to the shortURL task.

EPSS

Процентиль: 83%
0.0195
Низкий

8.1 High

CVSS3

Дефекты

CWE-918