Unrated severityOSV Advisory· Published Mar 23, 2018· Updated Sep 16, 2024
CVE-2018-1000138
CVE-2018-1000138
Description
I, Librarian version 4.8 and earlier contains a SSRF vulnerability in "url" parameter of getFromWeb in functions.php that can result in the attacker abusing functionality on the server to read or update internal resources.
Affected products
1- Range: 3.0, 3.1, 3.2, …
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
2- github.com/mkucej/i-librarian/blob/9535753a84bc615b210802d4c9542db73368d984/functions.phpmitrex_refsource_MISC
- github.com/mkucej/i-librarian/issues/120mitrex_refsource_MISC
News mentions
0No linked articles in our index yet.