Логотип exploitDog
bind:CVE-2024-25181
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2024-25181

Количество 2

Количество 2

nvd логотип

CVE-2024-25181

около 1 месяца назад

A critical vulnerability has been identified in givanz VvvebJs 1.7.2, which allows both Server-Side Request Forgery (SSRF) and arbitrary file reading. The vulnerability stems from improper handling of user-supplied URLs in the "file_get_contents" function within the "save.php" file.

CVSS3: 9.1
EPSS: Низкий
github логотип

GHSA-5r6q-cg35-jr9q

около 1 месяца назад

A critical vulnerability has been identified in givanz VvvebJs 1.7.2, which allows both Server-Side Request Forgery (SSRF) and arbitrary file reading. The vulnerability stems from improper handling of user-supplied URLs in the "file_get_contents" function within the "save.php" file.

CVSS3: 9.1
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2024-25181

A critical vulnerability has been identified in givanz VvvebJs 1.7.2, which allows both Server-Side Request Forgery (SSRF) and arbitrary file reading. The vulnerability stems from improper handling of user-supplied URLs in the "file_get_contents" function within the "save.php" file.

CVSS3: 9.1
0%
Низкий
около 1 месяца назад
github логотип
GHSA-5r6q-cg35-jr9q

A critical vulnerability has been identified in givanz VvvebJs 1.7.2, which allows both Server-Side Request Forgery (SSRF) and arbitrary file reading. The vulnerability stems from improper handling of user-supplied URLs in the "file_get_contents" function within the "save.php" file.

CVSS3: 9.1
0%
Низкий
около 1 месяца назад

Уязвимостей на страницу