Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-phx5-r46p-24fc

Опубликовано: 17 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 8

Описание

Mahara 1.8 before 1.8.7 and 1.9 before 1.9.5 and 1.10 before 1.10.3 and 15.04 before 15.04.0 are vulnerable to server-side request forgery attacks as not all processes of curl redirects are checked against a white or black list. Employing SafeCurl will prevent issues.

Mahara 1.8 before 1.8.7 and 1.9 before 1.9.5 and 1.10 before 1.10.3 and 15.04 before 15.04.0 are vulnerable to server-side request forgery attacks as not all processes of curl redirects are checked against a white or black list. Employing SafeCurl will prevent issues.

EPSS

Процентиль: 43%
0.00206
Низкий

8 High

CVSS3

Дефекты

CWE-918

Связанные уязвимости

CVSS3: 8
nvd
больше 8 лет назад

Mahara 1.8 before 1.8.7 and 1.9 before 1.9.5 and 1.10 before 1.10.3 and 15.04 before 15.04.0 are vulnerable to server-side request forgery attacks as not all processes of curl redirects are checked against a white or black list. Employing SafeCurl will prevent issues.

CVSS3: 8
debian
больше 8 лет назад

Mahara 1.8 before 1.8.7 and 1.9 before 1.9.5 and 1.10 before 1.10.3 an ...

EPSS

Процентиль: 43%
0.00206
Низкий

8 High

CVSS3

Дефекты

CWE-918