Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-9jm4-rg99-566c

Опубликовано: 14 мая 2022
Источник: github
Github: Прошло ревью
CVSS3: 7.5

Описание

phpBB Server-Side Request Forgery (SSRF)

phpBB version 3.2.0 is vulnerable to SSRF in the Remote Avatar function resulting allowing an attacker to perform port scanning, requesting internal content and potentially attacking such internal services via the web application.

Пакеты

Наименование

phpbb/phpbb

composer
Затронутые версииВерсия исправления

= 3.2.0

3.2.1

EPSS

Процентиль: 59%
0.0038
Низкий

7.5 High

CVSS3

Дефекты

CWE-918

Связанные уязвимости

CVSS3: 7.5
ubuntu
около 8 лет назад

phpBB version 3.2.0 is vulnerable to SSRF in the Remote Avatar function resulting allowing an attacker to perform port scanning, requesting internal content and potentially attacking such internal services via the web application.

CVSS3: 7.5
nvd
около 8 лет назад

phpBB version 3.2.0 is vulnerable to SSRF in the Remote Avatar function resulting allowing an attacker to perform port scanning, requesting internal content and potentially attacking such internal services via the web application.

CVSS3: 7.5
debian
около 8 лет назад

phpBB version 3.2.0 is vulnerable to SSRF in the Remote Avatar functio ...

EPSS

Процентиль: 59%
0.0038
Низкий

7.5 High

CVSS3

Дефекты

CWE-918