Описание
Blind Server-Side Request Forgery (SSRF) in the survey-import feature of
ObjectPlanet Opinio 7.26 rev12562 on
Web-based platforms allows an attacker to force the server to perform HTTP GET requests via crafted import requests
to an arbitrary destination.
Ссылки
- Release Notes
Уязвимые конфигурации
Конфигурация 1
cpe:2.3:a:objectplanet:opinio:7.26:*:*:*:*:*:*:*
EPSS
Процентиль: 15%
0.00048
Низкий
9.1 Critical
CVSS3
Дефекты
CWE-918
Связанные уязвимости
CVSS3: 9.1
github
2 месяца назад
Blind Server-Side Request Forgery (SSRF) in the survey-import feature of ObjectPlanet Opinio 7.26 rev12562 on Web-based platforms allows an attacker to force the server to perform HTTP GET requests via crafted import requests to an arbitrary destination.
EPSS
Процентиль: 15%
0.00048
Низкий
9.1 Critical
CVSS3
Дефекты
CWE-918