VYPR
Low severity2.0NVD Advisory· Published Oct 17, 2023· Updated Jun 17, 2026

CVE-2023-45152

CVE-2023-45152

Description

Engelsystem is a shift planning system for chaos events. A Blind SSRF in the "Import schedule" functionality makes it possible to perform a port scan against the local environment. This vulnerability has been fixed in commit ee7d30b33. If a patch cannot be deployed, operators should ensure that no HTTP(s) services listen on localhost and/or systems only reachable from the host running the engelsystem software. If such services are necessary, they should utilize additional authentication.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

3
  • cpe:2.3:a:engelsystem:engelsystem:*:*:*:*:*:*:*:*+ 2 more
    • cpe:2.3:a:engelsystem:engelsystem:*:*:*:*:*:*:*:*range: <2023-09-18
    • (no CPE)
    • (no CPE)range: < ee7d30b33

Patches

Vulnerability mechanics

References

2

News mentions

0

No linked articles in our index yet.