Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2022-39039

Опубликовано: 03 янв. 2023
Источник: nvd
CVSS3: 9.8
EPSS Низкий

Описание

aEnrich’s a+HRD has inadequate filtering for specific URL parameter. An unauthenticated remote attacker can exploit this vulnerability to send arbitrary HTTP(s) request to launch Server-Side Request Forgery (SSRF) attack, to perform arbitrary system command or disrupt service.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:aenrich:a\+hrd:6.8:*:*:*:*:*:*:*
cpe:2.3:a:aenrich:a\+hrd:7.0:*:*:*:*:*:*:*

EPSS

Процентиль: 81%
0.0147
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-918
CWE-918

Связанные уязвимости

CVSS3: 9.8
github
больше 2 лет назад

aEnrich’s a+HRD has inadequate filtering for specific URL parameter. An unauthenticated remote attacker can exploit this vulnerability to send arbitrary HTTP(s) request to launch Server-Side Request Forgery (SSRF) attack, to perform arbitrary system command or disrupt service.

EPSS

Процентиль: 81%
0.0147
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-918
CWE-918