VYPR

CWE-918

Server-Side Request Forgery (SSRF)

BaseIncomplete

Description

The web server receives a URL or similar request from an upstream component and retrieves the contents of this URL, but it does not sufficiently ensure that the request is being sent to the expected destination.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-664

CVEs mapped to this weakness (3,225)

page 158 of 162
  • CVE-2023-50266MedDec 15, 2023
    risk 0.00cvss 5.3epss 0.01

    Bazarr manages and downloads subtitles. In version 1.2.4, the proxy method in bazarr/bazarr/app/ui.py does not validate the user-controlled protocol and url variables and passes them to requests.get() without any sanitization, which leads to a blind server-side request forgery…

  • CVE-2023-46736MedDec 5, 2023
    risk 0.00cvss 5.3epss 0.00

    EspoCRM is an Open Source CRM (Customer Relationship Management) software. In affected versions there is Server-Side Request Forgery (SSRF) vulnerability via the upload image from url api. Users who have access to `the /Attachment/fromImageUrl` endpoint can specify URL to point…

  • CVE-2023-46746MedDec 1, 2023
    risk 0.00cvss 4.8epss 0.00

    PostHog provides open-source product analytics, session recording, feature flagging and A/B testing that you can self-host. A server-side request forgery (SSRF), which can only be exploited by authenticated users, was found in Posthog. Posthog did not verify whether a URL was…

  • CVE-2023-49094MedNov 30, 2023
    risk 0.00cvss 4.3epss 0.01

    Symbolicator is a symbolication service for native stacktraces and minidumps with symbol server support. An attacker could make Symbolicator send arbitrary GET HTTP requests to internal IP addresses by using a specially crafted HTTP endpoint. The response could be reflected to…

  • CVE-2023-48307LowNov 21, 2023
    risk 0.00cvss 3.5epss 0.01

    Nextcloud Mail is the mail app for Nextcloud, a self-hosted productivity platform. Starting in version 1.13.0 and prior to version 2.2.8 and 3.3.0, an attacker can use an unprotected endpoint in the Mail app to perform a SSRF attack. Nextcloud Mail app versions 2.2.8 and 3.3.0…

  • CVE-2023-48306MedNov 21, 2023
    risk 0.00cvss 5.0epss 0.01

    Nextcloud Server provides data storage for Nextcloud, an open source cloud platform. Starting in version 25.0.0 and prior to versions 25.0.11, 26.0.6, and 27.1.0 of Nextcloud Server and starting in version 22.0.0 and prior to versions 22.2.10.16, 23.0.12.11, 24.0.12.7, 25.0.11,…

  • CVE-2023-6124MedNov 14, 2023
    risk 0.00cvss 4.3epss 0.01

    Server-Side Request Forgery (SSRF) in GitHub repository salesagility/suitecrm prior to 7.14.2, 8.4.2, 7.12.14.

  • CVE-2023-47121LowNov 10, 2023
    risk 0.00cvss 3.4epss 0.01

    Discourse is an open source platform for community discussion. Prior to version 3.1.3 of the `stable` branch and version 3.2.0.beta3 of the `beta` and `tests-passed` branches, the embedding feature is susceptible to server side request forgery. The issue is patched in version…

  • CVE-2023-46730HigNov 7, 2023
    risk 0.00cvss 7.4epss 0.01

    Group-Office is an enterprise CRM and groupware tool. In affected versions there is full Server-Side Request Forgery (SSRF) vulnerability in the /api/upload.php endpoint. The /api/upload.php endpoint does not filter URLs which allows a malicious user to cause the server to make…

  • CVE-2023-46236HigOct 31, 2023
    risk 0.00cvss 8.6epss 0.00

    FOG is a free open-source cloning/imaging/rescue suite/inventory management system. Prior to version 1.5.10, a server-side-request-forgery (SSRF) vulnerability allowed an unauthenticated user to trigger a GET request as the server to an arbitrary endpoint and URL scheme. This…

  • CVE-2023-43798MedOct 30, 2023
    risk 0.00cvss 5.6epss 0.00

    BigBlueButton is an open-source virtual classroom. BigBlueButton prior to versions 2.6.12 and 2.7.0-rc.1 is vulnerable to Server-Side Request Forgery (SSRF). This issue is a bypass of CVE-2023-33176. A patch in versions 2.6.12 and 2.7.0-rc.1 disabled follow redirect at…

  • CVE-2023-45152LowOct 17, 2023
    risk 0.00cvss 2.0epss 0.00

    Engelsystem is a shift planning system for chaos events. A Blind SSRF in the "Import schedule" functionality makes it possible to perform a port scan against the local environment. This vulnerability has been fixed in commit ee7d30b33. If a patch cannot be deployed, operators…

  • CVE-2023-45660MedOct 16, 2023
    risk 0.00cvss 4.3epss 0.01

    Nextcloud mail is an email app for the Nextcloud home server platform. In affected versions a missing check of origin, target and cookies allows for an attacker to abuse the proxy endpoint to denial of service a third server. It is recommended that the Nextcloud Mail is upgraded…

  • CVE-2023-44384MedOct 6, 2023
    risk 0.00cvss 4.1epss 0.00

    Discourse-jira is a Discourse plugin allows Jira projects, issue types, fields and field options will be synced automatically. An administrator user can make an SSRF attack by setting the Jira URL to an arbitrary location and enabling the `discourse_jira_verbose_log` site…

  • CVE-2023-42450MedSep 19, 2023
    risk 0.00cvss 5.4epss 0.00

    Mastodon is a free, open-source social network server based on ActivityPub. Starting in version 4.2.0-beta1 and prior to version 4.2.0-rc2, by crafting specific input, attackers can inject arbitrary data into HTTP requests issued by Mastodon. This can be used to perform confused…

  • CVE-2023-4878MedSep 10, 2023
    risk 0.00cvss 5.4epss 0.00

    Server-Side Request Forgery (SSRF) in GitHub repository instantsoft/icms2 prior to 2.16.1-git.

  • CVE-2023-41055HigSep 4, 2023
    risk 0.00cvss 7.5epss 0.01

    LibreY is a fork of LibreX, a framework-less and javascript-free privacy respecting meta search engine. LibreY is subject to a Server-Side Request Forgery (SSRF) vulnerability in the `engines/google/text.php` and `engines/duckduckgo/text.php` files in versions before commit…

  • CVE-2023-41054HigSep 4, 2023
    risk 0.00cvss 8.2epss 0.01

    LibreY is a fork of LibreX, a framework-less and javascript-free privacy respecting meta search engine. LibreY is subject to a Server-Side Request Forgery (SSRF) vulnerability in the `image_proxy.php` file of LibreY before commit 8f9b9803f231e2954e5b49987a532d28fe50a627. This…

  • CVE-2023-4651MedAug 31, 2023
    risk 0.00cvss 5.4epss 0.00

    Server-Side Request Forgery (SSRF) in GitHub repository instantsoft/icms2 prior to 2.16.1.

  • CVE-2023-4624LowAug 30, 2023
    risk 0.00cvss 2.4epss 0.01

    Server-Side Request Forgery (SSRF) in GitHub repository bookstackapp/bookstack prior to v23.08.