VYPR

CWE-918

Server-Side Request Forgery (SSRF)

BaseIncomplete

Description

The web server receives a URL or similar request from an upstream component and retrieves the contents of this URL, but it does not sufficiently ensure that the request is being sent to the expected destination.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-664

CVEs mapped to this weakness (3,680)

page 133 of 184
  • CVE-2024-12989MedDec 27, 2024
    risk 0.34cvss 5.3epss 0.00

    A vulnerability was found in WISI Tangram GT31 up to 20241214 and classified as problematic. Affected by this issue is some unknown functionality of the component HTTP Request Handler. The manipulation leads to server-side request forgery. The attack may be launched remotely.…

  • CVE-2024-6538MedNov 25, 2024
    risk 0.34cvss 5.3epss 0.01

    A flaw was found in OpenShift Console. A Server Side Request Forgery (SSRF) attack can happen if an attacker supplies all or part of a URL to the server to query. The server is considered to be in a privileged network position and can often reach exposed services that aren't…

  • CVE-2024-45291MedOct 7, 2024
    risk 0.34cvss 6.3epss 0.01

    PHPSpreadsheet is a pure PHP library for reading and writing spreadsheet files. It's possible for an attacker to construct an XLSX file that links images from arbitrary paths. When embedding images has been enabled in HTML writer with `$writer->setEmbedImages(true);` those files…

  • CVE-2024-9410MedOct 4, 2024
    risk 0.34cvss 5.3epss 0.00

    Ada.cx's Sentry configuration allowed for blind server-side request forgeries (SSRF) through the use of a data scraping endpoint.

  • CVE-2021-38132MedSep 12, 2024
    risk 0.34cvss 5.3epss 0.00

    Possible External Service Interaction attack in eDirectory has been discovered in OpenText™ eDirectory. This impact all version before 9.2.6.0000.

  • CVE-2024-34580MedJun 26, 2024
    risk 0.34cvss 5.3epss 0.00

    Apache XML Security for C++ through 2.0.4 implements the XML Signature Syntax and Processing (XMLDsig) specification without protection against an SSRF payload in a KeyInfo element. NOTE: the project disputes this CVE Record on the grounds that any vulnerabilities are the result…

  • CVE-2024-3970MedMay 15, 2024
    risk 0.34cvss 5.3epss 0.01

    Server Side Request Forgery vulnerability has been discovered in OpenText™ iManager 3.2.6.0200. This could lead to senstive information disclosure by directory traversal.

  • CVE-2024-3485MedMay 15, 2024
    risk 0.34cvss 5.3epss 0.00

    Server Side Request Forgery vulnerability has been discovered in OpenText™ iManager 3.2.6.0200. This could lead to senstive information disclosure.

  • CVE-2024-4894MedMay 15, 2024
    risk 0.34cvss 5.3epss 0.00

    ITPison OMICARD EDM fails to properly filter specific URL parameter, allowing unauthenticated remote attackers to modify the parameters and conduct Server-Side Request Forgery (SSRF) attacks. This vulnerability enables attackers to probe internal network information.

  • CVE-2024-33117MedMay 6, 2024
    risk 0.34cvss 5.3epss 0.00

    crmeb_java v1.3.4 was discovered to contain a Server-Side Request Forgery (SSRF) via the mergeList method in class com.zbkj.front.pub.ImageMergeController.

  • CVE-2024-27898MedApr 9, 2024
    risk 0.34cvss 5.3epss 0.00

    SAP NetWeaver application, due to insufficient input validation, allows an attacker to send a crafted request from a vulnerable web application targeting internal systems behind firewalls that are normally inaccessible to an attacker from the external network, resulting in…

  • CVE-2024-31215MedApr 4, 2024
    risk 0.34cvss 6.3epss 0.01

    Mobile Security Framework (MobSF) is a security research platform for mobile applications in Android, iOS and Windows Mobile. A SSRF vulnerability in firebase database check logic. The attacker can cause the server to make a connection to internal-only services within the…

  • CVE-2024-27563MedMar 5, 2024
    risk 0.34cvss 5.3epss 0.00

    A Server-Side Request Forgery (SSRF) in the getFileFromRepo function of WonderCMS v3.1.3 allows attackers to force the application to make arbitrary requests via injection of crafted URLs into the pluginThemeUrl parameter.

  • CVE-2024-21498MedFeb 17, 2024
    risk 0.34cvss 5.3epss 0.01

    All versions of the package github.com/greenpau/caddy-security are vulnerable to Server-side Request Forgery (SSRF) via X-Forwarded-Host header manipulation. An attacker can expose sensitive information, interact with internal services, or exploit other vulnerabilities within…

  • CVE-2024-1063MedJan 30, 2024
    risk 0.34cvss 5.3epss 0.00

    Appwrite <= v1.4.13 is affected by a Server-Side Request Forgery (SSRF) via the '/v1/avatars/favicon' endpoint due to an incomplete fix of CVE-2023-27159.

  • CVE-2024-22648MedJan 30, 2024
    risk 0.34cvss 5.3epss 0.01

    A Blind SSRF vulnerability exists in the "Crawl Meta Data" functionality of SEO Panel version 4.10.0. This makes it possible for remote attackers to scan ports in the local environment.

  • CVE-2024-23330MedJan 23, 2024
    risk 0.34cvss 5.3epss 0.00

    Tuta is an encrypted email service. In versions prior to 119.10, an attacker can attach an image in a html mail which is loaded from external resource in the default setting, which should prevent loading of external resources. When displaying emails containing external content,…

  • CVE-2023-50259MedDec 22, 2023
    risk 0.34cvss 5.3epss 0.01

    Medusa is an automatic video library manager for TV shows. Versions prior to 1.0.19 are vulnerable to unauthenticated blind server-side request forgery (SSRF). The `testslack` request handler in `medusa/server/web/home/handler.py` does not validate the user-controlled…

  • CVE-2023-48379MedDec 15, 2023
    risk 0.34cvss 5.3epss 0.01

    Softnext Mail SQR Expert is an email management platform, it has inadequate filtering for a specific URL parameter within a specific function. An unauthenticated remote attacker can perform Blind SSRF attack to discover internal network topology base on URL error response.

  • CVE-2023-24515MedAug 22, 2023
    risk 0.34cvss 5.2epss 0.00

    Server-Side Request Forgery (SSRF) vulnerability in API checker of Pandora FMS. Application does not have a check on the URL scheme used while retrieving API URL. Rather than validating the http/https scheme, the application allows other scheme such as file, which could allow a…