Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-5jj7-gjcq-hrc8

Опубликовано: 15 мая 2024
Источник: github
Github: Не прошло ревью
CVSS3: 5.3

Описание

ITPison OMICARD EDM fails to properly filter specific URL parameter, allowing unauthenticated remote attackers to modify the parameters and conduct Server-Side Request Forgery (SSRF) attacks. This vulnerability enables attackers to probe internal network information.

ITPison OMICARD EDM fails to properly filter specific URL parameter, allowing unauthenticated remote attackers to modify the parameters and conduct Server-Side Request Forgery (SSRF) attacks. This vulnerability enables attackers to probe internal network information.

EPSS

Процентиль: 39%
0.00171
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-918

Связанные уязвимости

CVSS3: 5.3
nvd
больше 1 года назад

ITPison OMICARD EDM fails to properly filter specific URL parameter, allowing unauthenticated remote attackers to modify the parameters and conduct Server-Side Request Forgery (SSRF) attacks. This vulnerability enables attackers to probe internal network information.

EPSS

Процентиль: 39%
0.00171
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-918