VYPR

CWE-918

Server-Side Request Forgery (SSRF)

BaseIncomplete

Description

The web server receives a URL or similar request from an upstream component and retrieves the contents of this URL, but it does not sufficiently ensure that the request is being sent to the expected destination.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-664

CVEs mapped to this weakness (3,682)

page 101 of 185
  • CVE-2024-0304MedJan 8, 2024
    risk 0.41cvss 6.3epss 0.01

    A vulnerability has been found in Youke365 up to 1.5.3 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /app/api/controller/collect.php. The manipulation of the argument url leads to server-side request forgery. The attack can be…

  • CVE-2024-0303MedJan 8, 2024
    risk 0.41cvss 6.3epss 0.01

    A vulnerability, which was classified as critical, was found in Youke365 up to 1.5.3. Affected is an unknown function of the file /app/api/controller/caiji.php of the component Parameter Handler. The manipulation of the argument url leads to server-side request forgery. It is…

  • CVE-2023-7037MedDec 21, 2023
    risk 0.41cvss 6.3epss 0.01

    A vulnerability was found in automad up to 1.10.9. It has been declared as critical. This vulnerability affects the function import of the file FileController.php. The manipulation of the argument importUrl leads to server-side request forgery. The attack can be initiated…

  • CVE-2022-45835MedNov 13, 2023
    risk 0.41cvss 5.8epss 0.38

    Server-Side Request Forgery (SSRF) vulnerability in PhonePe PhonePe Payment Solutions.This issue affects PhonePe Payment Solutions: from n/a through 1.0.15.

  • CVE-2023-42812MedSep 22, 2023
    risk 0.41cvss 6.3epss 0.00

    Galaxy is an open-source platform for FAIR data analysis. Prior to version 22.05, Galaxy is vulnerable to server-side request forgery, which allows a malicious to issue arbitrary HTTP/HTTPS requests from the application server to internal hosts and read their responses. Version…

  • CVE-2023-3238MedJun 14, 2023
    risk 0.41cvss 6.3epss 0.01

    A vulnerability, which was classified as critical, has been found in OTCMS up to 6.62. This issue affects some unknown processing of the file /admin/read.php?mudi=getSignal. The manipulation of the argument signalUrl leads to server-side request forgery. The attack may be…

  • CVE-2023-3236MedJun 14, 2023
    risk 0.41cvss 6.3epss 0.01

    A vulnerability classified as critical has been found in mccms up to 2.6.5. This affects the function pic_save of the file sys/apps/controllers/admin/Comic.php. The manipulation of the argument pic leads to server-side request forgery. It is possible to initiate the attack…

  • CVE-2023-3235MedJun 14, 2023
    risk 0.41cvss 6.3epss 0.01

    A vulnerability was found in mccms up to 2.6.5. It has been rated as critical. Affected by this issue is the function pic_api of the file sys/apps/controllers/admin/Comic.php. The manipulation of the argument url leads to server-side request forgery. The attack may be launched…

  • CVE-2023-3233MedJun 14, 2023
    risk 0.41cvss 6.3epss 0.01

    A vulnerability was found in Zhong Bang CRMEB up to 4.6.0. It has been classified as critical. Affected is the function get_image_base64 of the file api/controller/v1/PublicController.php. The manipulation leads to server-side request forgery. It is possible to launch the attack…

  • CVE-2023-3015MedMay 31, 2023
    risk 0.41cvss 6.3epss 0.01

    A vulnerability has been found in yiwent Vip Video Analysis 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file data/title.php. The manipulation of the argument titurl leads to server-side request forgery. The attack can be…

  • CVE-2023-2927MedMay 27, 2023
    risk 0.41cvss 6.3epss 0.01

    A vulnerability was found in JIZHICMS 2.4.5. It has been classified as critical. Affected is the function index of the file TemplateController.php. The manipulation of the argument webapi leads to server-side request forgery. It is possible to launch the attack remotely. The…

  • CVE-2023-1971MedApr 10, 2023
    risk 0.41cvss 6.3epss 0.01

    ** UNSUPPORTED WHEN ASSIGNED ** A vulnerability, which was classified as critical, was found in yuan1994 tpAdmin 1.3.12. Affected is the function remote of the file application\admin\controller\Upload.php. The manipulation of the argument url leads to server-side request…

  • CVE-2023-1634MedMar 25, 2023
    risk 0.41cvss 6.3epss 0.01

    A vulnerability was found in OTCMS 6.72. It has been classified as critical. Affected is the function UseCurl of the file /admin/info_deal.php of the component URL Parameter Handler. The manipulation leads to server-side request forgery. It is possible to launch the attack…

  • CVE-2023-1046MedFeb 26, 2023
    risk 0.41cvss 6.3epss 0.01

    A vulnerability classified as critical has been found in MuYuCMS 2.2. This affects an unknown part of the file /admin.php/update/getFile.html. The manipulation of the argument url leads to server-side request forgery. It is possible to initiate the attack remotely. The exploit…

  • CVE-2023-22936MedFeb 14, 2023
    risk 0.41cvss 6.3epss 0.00

    In Splunk Enterprise versions below 8.1.13, 8.2.10, and 9.0.4, the ‘search_listener’ parameter in a search allows for a blind server-side request forgery (SSRF) by an authenticated user. The initiator of the request cannot see the response without the presence of an…

  • CVE-2022-24739HigMar 8, 2022
    risk 0.41cvss 7.3epss 0.01

    alltube is an html front end for youtube-dl. On releases prior to 3.0.3, an attacker could craft a special HTML page to trigger either an open redirect attack or a Server-Side Request Forgery attack (depending on how AllTube is configured). The impact is mitigated by the fact…

  • CVE-2020-4974MedJul 28, 2021
    risk 0.41cvss 6.3epss 0.01

    IBM Jazz Foundation products are vulnerable to server side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from the system, potentially leading to network enumeration or facilitating other attacks. IBM X-Force ID: 192434.

  • CVE-2020-8555MedJun 5, 2020
    risk 0.41cvss 6.3epss 0.04

    The Kubernetes kube-controller-manager in versions v1.0-1.14, versions prior to v1.15.12, v1.16.9, v1.17.5, and version v1.18.0 are vulnerable to a Server Side Request Forgery (SSRF) that allows certain authorized users to leak up to 500 bytes of arbitrary information from…

  • CVE-2020-4294MedApr 15, 2020
    risk 0.41cvss 6.3epss 0.01

    IBM QRadar 7.3.0 to 7.3.3 Patch 2 is vulnerable to Server Side Request Forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from the system, potentially leading to network enumeration or facilitating other attacks. IBM X-ForceID: 176404.

  • CVE-2017-7553MedSep 29, 2017
    risk 0.41cvss 6.3epss 0.01

    The external_request api call in App Studio (millicore) allows server side request forgery (SSRF). An attacker could use this flaw to probe the network internal resources, and access restricted endpoints.