CVE-2024-48232
CVE-2024-48232
Título es
CVE-2024-48232
Vie, 25/10/2024 – 21:15
Gravedad 2.0 Txt
Pendiente de análisis
Título en
CVE-2024-48232
Descripción en
An issue was found in mipjz 5.0.5. In the mipPost method of \app\setting\controller\ApiAdminTool.php, the value of the postAddress parameter is not processed and is directly passed into curl_exec execution and output, resulting in a Server-side request forgery (SSRF) vulnerability that can read server files.
25/10/2024
25/10/2024
Gravedad 3.1 Txt Gravedad 3.1 (CVSS 3.1 Base Score)
Pendiente de análisis
Referencias
Enviar en el boletín
Off
