Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-2g36-547g-jq4m

Опубликовано: 15 окт. 2022
Источник: github
Github: Не прошло ревью
CVSS3: 9.1

Описание

A security issue was discovered in WeBid <=1.2.2. A Server-Side Request Forgery (SSRF) vulnerability in the admin/theme.php file allows remote attackers to inject payloads via theme parameters to read files across directories.

A security issue was discovered in WeBid <=1.2.2. A Server-Side Request Forgery (SSRF) vulnerability in the admin/theme.php file allows remote attackers to inject payloads via theme parameters to read files across directories.

EPSS

Процентиль: 46%
0.00237
Низкий

9.1 Critical

CVSS3

Дефекты

CWE-918

Связанные уязвимости

CVSS3: 9.1
nvd
больше 3 лет назад

A security issue was discovered in WeBid <=1.2.2. A Server-Side Request Forgery (SSRF) vulnerability in the admin/theme.php file allows remote attackers to inject payloads via theme parameters to read files across directories.

EPSS

Процентиль: 46%
0.00237
Низкий

9.1 Critical

CVSS3

Дефекты

CWE-918