Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2024-3448

Опубликовано: 10 апр. 2024
Источник: nvd
CVSS3: 5
EPSS Низкий

Описание

Users with low privileges can perform certain AJAX actions. In this vulnerability instance, improper access to ajax?action=plugin:focus:checkIframeAvailability leads to a Server-Side Request Forgery by analyzing the error messages returned from the back-end. Allowing an attacker to perform a port scan in the back-end. At the time of publication of the CVE no patch is available.

EPSS

Процентиль: 41%
0.00194
Низкий

5 Medium

CVSS3

Дефекты

CWE-918

Связанные уязвимости

CVSS3: 5
github
почти 2 года назад

Users with low privileges can perform certain AJAX actions. In this vulnerability instance, improper access to ajax?action=plugin:focus:checkIframeAvailability leads to a Server-Side Request Forgery by analyzing the error messages returned from the back-end. Allowing an attacker to perform a port scan in the back-end. At the time of publication of the CVE no patch is available.

EPSS

Процентиль: 41%
0.00194
Низкий

5 Medium

CVSS3

Дефекты

CWE-918