Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-8pp6-8x4q-c5mx

Опубликовано: 30 мар. 2022
Источник: github
Github: Прошло ревью
CVSS3: 7.6

Описание

Server side request forgery in C1 CMS

C1 CMS is an open-source, .NET based Content Management System (CMS). Versions prior to 6.12 allow an authenticated user to exploit Server Side Request Forgery (SSRF) by causing the server to make arbitrary GET requests to other servers in the local network or on localhost. The attacker may also truncate arbitrary files to zero size (effectively delete them) leading to denial of service (DoS) or altering application logic. The authenticated user may unknowingly perform the actions by visiting a specially crafted site. Patched in C1 CMS v6.12, no known workarounds exist.

Пакеты

Наименование

C1CMS.Assemblies

nuget
Затронутые версииВерсия исправления

<= 6.11.7982.26191

6.12.8122.18346

EPSS

Процентиль: 50%
0.00266
Низкий

7.6 High

CVSS3

Дефекты

CWE-918

Связанные уязвимости

CVSS3: 7.6
nvd
почти 4 года назад

C1 CMS is an open-source, .NET based Content Management System (CMS). Versions prior to 6.12 allow an authenticated user to exploit Server Side Request Forgery (SSRF) by causing the server to make arbitrary GET requests to other servers in the local network or on localhost. The attacker may also truncate arbitrary files to zero size (effectively delete them) leading to denial of service (DoS) or altering application logic. The authenticated user may unknowingly perform the actions by visiting a specially crafted site. Patched in C1 CMS v6.12, no known workarounds exist.

EPSS

Процентиль: 50%
0.00266
Низкий

7.6 High

CVSS3

Дефекты

CWE-918