VYPR
Medium severity4.9NVD Advisory· Published Oct 25, 2024· Updated Apr 15, 2026

CVE-2024-48234

CVE-2024-48234

Description

An issue was discovered in mipjz 5.0.5. In the push method of app\tag\controller\ApiAdminTag.php the value of the postAddress parameter is not processed and is directly passed into curl_exec execution and output, resulting in Server-side request forgery (SSRF) vulnerability that can read server files.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

2
  • Sansanyun/Mipjzreferences2 versions
    (expand)+ 1 more
    • (no CPE)
    • (no CPE)range: = 5.0.5

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.