Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-r62f-j7fr-mvvx

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью

Описание

A SSRF vulnerability exists in Winmail 6.5 in app.php in the key parameter when HTTPS is on. An attacker can use this vulnerability to cause the server to send a request to a specific URL. An attacker can modify the request header 'HOST' value to cause the server to send the request.

A SSRF vulnerability exists in Winmail 6.5 in app.php in the key parameter when HTTPS is on. An attacker can use this vulnerability to cause the server to send a request to a specific URL. An attacker can modify the request header 'HOST' value to cause the server to send the request.

EPSS

Процентиль: 51%
0.00278
Низкий

Дефекты

CWE-918

Связанные уязвимости

CVSS3: 7.5
nvd
около 5 лет назад

A SSRF vulnerability exists in Winmail 6.5 in app.php in the key parameter when HTTPS is on. An attacker can use this vulnerability to cause the server to send a request to a specific URL. An attacker can modify the request header 'HOST' value to cause the server to send the request.

EPSS

Процентиль: 51%
0.00278
Низкий

Дефекты

CWE-918