Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-943p-qf6q-5m99

Опубликовано: 17 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 8.6

Описание

The sendRequest method in HTTPClient Class in file /inc/HTTPClient.php in DokuWiki 2016-06-26a and older, when media file fetching is enabled, has no way to restrict access to private networks. This allows users to scan ports of internal networks via SSRF, such as 10.0.0.1/8, 172.16.0.0/12, and 192.168.0.0/16.

The sendRequest method in HTTPClient Class in file /inc/HTTPClient.php in DokuWiki 2016-06-26a and older, when media file fetching is enabled, has no way to restrict access to private networks. This allows users to scan ports of internal networks via SSRF, such as 10.0.0.1/8, 172.16.0.0/12, and 192.168.0.0/16.

EPSS

Процентиль: 68%
0.00559
Низкий

8.6 High

CVSS3

Дефекты

CWE-918

Связанные уязвимости

CVSS3: 8.6
ubuntu
больше 9 лет назад

The sendRequest method in HTTPClient Class in file /inc/HTTPClient.php in DokuWiki 2016-06-26a and older, when media file fetching is enabled, has no way to restrict access to private networks. This allows users to scan ports of internal networks via SSRF, such as 10.0.0.1/8, 172.16.0.0/12, and 192.168.0.0/16.

CVSS3: 8.6
nvd
больше 9 лет назад

The sendRequest method in HTTPClient Class in file /inc/HTTPClient.php in DokuWiki 2016-06-26a and older, when media file fetching is enabled, has no way to restrict access to private networks. This allows users to scan ports of internal networks via SSRF, such as 10.0.0.1/8, 172.16.0.0/12, and 192.168.0.0/16.

CVSS3: 8.6
debian
больше 9 лет назад

The sendRequest method in HTTPClient Class in file /inc/HTTPClient.php ...

EPSS

Процентиль: 68%
0.00559
Низкий

8.6 High

CVSS3

Дефекты

CWE-918