Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-954r-8vpp-vj52

Опубликовано: 10 июл. 2024
Источник: github
Github: Не прошло ревью
CVSS4: 8.7

Описание

Insecure handling of GET header parameter file included in requests being sent to an instance of the open-source project Phoniebox allows an attacker to create a website, which – when visited by a user – will send malicious requests to multiple hosts on the local network. If such a request reaches the server, it will cause one of the following (depending on the chosen payload): shell command execution, reflected XSS or cross-site request forgery.

This issue affects Phoniebox in all releases through 2.7. Newer releases were not tested, but they might also be vulnerable.

Insecure handling of GET header parameter file included in requests being sent to an instance of the open-source project Phoniebox allows an attacker to create a website, which – when visited by a user – will send malicious requests to multiple hosts on the local network. If such a request reaches the server, it will cause one of the following (depending on the chosen payload): shell command execution, reflected XSS or cross-site request forgery.

This issue affects Phoniebox in all releases through 2.7. Newer releases were not tested, but they might also be vulnerable.

EPSS

Процентиль: 56%
0.00338
Низкий

8.7 High

CVSS4

Дефекты

CWE-352

Связанные уязвимости

nvd
больше 1 года назад

Insecure handling of GET header parameter file included in requests being sent to an instance of the open-source project Phoniebox allows an attacker to create a website, which – when visited by a user – will send malicious requests to multiple hosts on the local network. If such a request reaches the server, it will cause one of the following (depending on the chosen payload): shell command execution, reflected XSS or cross-site request forgery. This issue affects Phoniebox in all releases through 2.7. Newer 2.x releases were not tested, but they might also be vulnerable.  Phoniebox in version 3.0 and higher are not affected.

EPSS

Процентиль: 56%
0.00338
Низкий

8.7 High

CVSS4

Дефекты

CWE-352