VYPR

CWE-918

Server-Side Request Forgery (SSRF)

BaseIncomplete

Description

The web server receives a URL or similar request from an upstream component and retrieves the contents of this URL, but it does not sufficiently ensure that the request is being sent to the expected destination.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-664

CVEs mapped to this weakness (3,621)

page 50 of 182
  • CVE-2021-22026HigAug 30, 2021
    risk 0.49cvss 7.5epss 0.01

    The vRealize Operations Manager API (8.x prior to 8.5) contains a Server Side Request Forgery in an end point. An unauthenticated malicious actor with network access to the vRealize Operations Manager API can perform a Server Side Request Forgery attack leading to information…

  • CVE-2020-23079HigJul 12, 2021
    risk 0.49cvss 7.5epss 0.01

    SSRF vulnerability in Halo <=1.3.2 exists in the SMTP configuration, which can detect the server intranet.

  • CVE-2020-20582HigJul 8, 2021
    risk 0.49cvss 7.5epss 0.01

    A server side request forgery (SSRF) vulnerability in /ApiAdminDomainSettings.php of MipCMS 5.0.1 allows attackers to access sensitive information.

  • CVE-2020-24149HigJul 7, 2021
    risk 0.49cvss 7.5epss 0.02

    Server-side request forgery (SSRF) in the Podcast Importer SecondLine (podcast-importer-secondline) plugin 1.1.4 for WordPress via the podcast_feed parameter in a secondline_import_initialize action to the secondlinepodcastimport page.

  • CVE-2020-35970HigJun 3, 2021
    risk 0.49cvss 7.5epss 0.01

    An issue was discovered in YzmCMS 5.8. There is a SSRF vulnerability in the background collection management that allows arbitrary file read.

  • CVE-2021-33511HigMay 21, 2021
    risk 0.49cvss 7.5epss 0.01

    Plone though 5.2.4 allows SSRF via the lxml parser. This affects Diazo themes, Dexterity TTW schemas, and modeleditors in plone.app.theming, plone.app.dexterity, and plone.supermodel.

  • CVE-2021-31910HigMay 11, 2021
    risk 0.49cvss 7.5epss 0.01

    In JetBrains TeamCity before 2020.2.3, information disclosure via SSRF was possible.

  • CVE-2020-22002HigApr 29, 2021
    risk 0.49cvss 7.5epss 0.01

    An Unauthenticated Server-Side Request Forgery (SSRF) vulnerability exists in Inim Electronics Smartliving SmartLAN/G/SI <=6.x within the GetImage functionality. The application parses user supplied data in the GET parameter 'host' to construct an image request to the service…

  • CVE-2021-24150HigApr 5, 2021
    risk 0.49cvss 7.5epss 0.04

    The LikeBtn WordPress Like Button Rating ♥ LikeBtn WordPress plugin before 2.6.32 was vulnerable to Unauthenticated Full-Read Server-Side Request Forgery (SSRF).

  • CVE-2020-19613HigApr 1, 2021
    risk 0.49cvss 7.5epss 0.01

    Server Side Request Forgery (SSRF) vulnerability in saveUrlAs function in ImagesService.java in sunkaifei FlyCMS version 20190503.

  • CVE-2020-35558HigFeb 16, 2021
    risk 0.49cvss 7.5epss 0.01

    An issue was discovered in MB connect line mymbCONNECT24, mbCONNECT24 and Helmholz myREX24 and myREX24.virtual through 2.11.2. There is an SSRF in the in the MySQL access check, allowing an attacker to scan for open ports and gain some information about possible credentials.

  • CVE-2020-35667HigFeb 3, 2021
    risk 0.49cvss 7.5epss 0.01

    JetBrains TeamCity Plugin before 2020.2.85695 SSRF. Vulnerability that could potentially expose user credentials.

  • CVE-2020-23776HigJan 26, 2021
    risk 0.49cvss 7.5epss 0.01

    A SSRF vulnerability exists in Winmail 6.5 in app.php in the key parameter when HTTPS is on. An attacker can use this vulnerability to cause the server to send a request to a specific URL. An attacker can modify the request header 'HOST' value to cause the server to send the…

  • CVE-2020-24641HigJan 15, 2021
    risk 0.49cvss 7.5epss 0.01

    In Aruba AirWave Glass before 1.3.3, there is a Server-Side Request Forgery vulnerability through an unauthenticated endpoint that if successfully exploited can result in disclosure of sensitive information. This can be used to perform an authentication bypass and ultimately…

  • CVE-2020-26032HigDec 28, 2020
    risk 0.49cvss 7.5epss 0.01

    An SSRF issue was discovered in Zammad before 3.4.1. The SMS configuration interface for Massenversand is implemented in a way that renders the result of a test request to the User. An attacker can use this to request any URL via a GET request from the network interface of the…

  • CVE-2020-8464HigDec 17, 2020
    risk 0.49cvss 7.5epss 0.06

    A vulnerability in Trend Micro InterScan Web Security Virtual Appliance 6.5 SP2 could allow an attacker to send requests that appear to come from the localhost which could expose the product's admin interface to users who would not normally have access.

  • CVE-2020-28043HigNov 2, 2020
    risk 0.49cvss 7.5epss 0.01

    MISP through 2.4.133 allows SSRF in the REST client via the use_full_path parameter with an arbitrary URL.

  • CVE-2020-24898HigAug 29, 2020
    risk 0.49cvss 7.6epss 0.01

    The Table Filter and Charts for Confluence Server app before 5.3.26 (for Atlassian Confluence) allows SSRF via the "Table from CSV" macro (URL parameter).

  • CVE-2020-15823HigAug 8, 2020
    risk 0.49cvss 7.5epss 0.02

    JetBrains YouTrack before 2020.2.8873 is vulnerable to SSRF in the Workflow component.

  • CVE-2020-13650HigJun 15, 2020
    risk 0.49cvss 7.5epss 0.01

    An issue was discovered in DigDash 2018R2 before p20200210 and 2019R1 before p20200210. The login page is vulnerable to Server-Side Request Forgery (SSRF) that allows use of the application as a proxy. Sent to an external server, a forged request discloses application…