Описание
Book Stack version 23.10.2 allows filtering local files on the server. This is possible because the application is vulnerable to SSRF.
Ссылки
- ExploitThird Party Advisory
- ProductRelease NotesVendor Advisory
- ExploitThird Party Advisory
- ProductRelease NotesVendor Advisory
Уязвимые конфигурации
Конфигурация 1
cpe:2.3:a:bookstackapp:bookstack:23.10.2:*:*:*:*:*:*:*
EPSS
Процентиль: 94%
0.13376
Средний
6.5 Medium
CVSS3
Дефекты
CWE-918
CWE-918
Связанные уязвимости
CVSS3: 7.1
github
около 2 лет назад
Book Stack version 23.10.2 allows filtering local files on the server. This is possible because the application is vulnerable to SSRF.
EPSS
Процентиль: 94%
0.13376
Средний
6.5 Medium
CVSS3
Дефекты
CWE-918
CWE-918