VYPR

CWE-918

Server-Side Request Forgery (SSRF)

BaseIncomplete

Description

The web server receives a URL or similar request from an upstream component and retrieves the contents of this URL, but it does not sufficiently ensure that the request is being sent to the expected destination.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-664

CVEs mapped to this weakness (3,621)

page 7 of 182
  • CVE-2023-40630CriDec 14, 2023
    risk 0.64cvss 9.8epss 0.01

    Unauthenticated LFI/SSRF in JCDashboards component for Joomla.

  • CVE-2023-48910CriDec 4, 2023
    risk 0.64cvss 9.8epss 0.01

    Microcks up to 1.17.1 was discovered to contain a Server-Side Request Forgery (SSRF) via the component /jobs and /artifact/download. This vulnerability allows attackers to access network resources and sensitive information via a crafted GET request.

  • CVE-2023-46480CriNov 27, 2023
    risk 0.64cvss 9.8epss 0.02

    An issue in OwnCast v.0.1.1 allows a remote attacker to execute arbitrary code and obtain sensitive information via the authHost parameter of the indieauth function.

  • CVE-2023-5974CriNov 27, 2023
    risk 0.64cvss 9.8epss 0.03

    The WPB Show Core WordPress plugin through 2.2 is vulnerable to server-side request forgery (SSRF) via the `path` parameter.

  • CVE-2023-43982CriNov 3, 2023
    risk 0.64cvss 9.8epss 0.01

    Bon Presta boninstagramcarousel between v5.2.1 to v7.0.0 was discovered to contain a Server-Side Request Forgery (SSRF) via the url parameter at insta_parser.php. This vulnerability allows attackers to use the vulnerable website as proxy to attack other websites or exfiltrate…

  • CVE-2023-3744CriOct 2, 2023
    risk 0.64cvss 9.9epss 0.00

    Server-Side Request Forgery vulnerability in SLims version 9.6.0. This vulnerability could allow an authenticated attacker to send requests to internal services or upload the contents of relevant files via the "scrape_image.php" file in the imageURL parameter.

  • CVE-2023-43654CriSep 28, 2023
    risk 0.64cvss 10.0epss 0.35

    TorchServe is a tool for serving and scaling PyTorch models in production. TorchServe default configuration lacks proper input validation, enabling third parties to invoke remote HTTP download requests and write files to the disk. This issue could be taken advantage of to…

  • CVE-2023-41449CriSep 27, 2023
    risk 0.64cvss 9.8epss 0.01

    An issue in phpkobo AjaxNewsTicker v.1.0.5 allows a remote attacker to execute arbitrary code via a crafted payload to the reque parameter.

  • CVE-2023-42398CriSep 15, 2023
    risk 0.64cvss 9.8epss 0.02

    An issue in zzCMS v.2023 allows a remote attacker to execute arbitrary code and obtain sensitive information via the ueditor component in controller.php.

  • CVE-2023-35175CriJun 30, 2023
    risk 0.64cvss 9.8epss 0.01

    Certain HP LaserJet Pro print products are potentially vulnerable to Potential Remote Code Execution and/or Elevation of Privilege via Server-Side Request Forgery (SSRF) using the Web Service Eventing model.

  • CVE-2018-17452CriApr 15, 2023
    risk 0.64cvss 9.8epss 0.01

    An issue was discovered in GitLab Community and Enterprise Edition before 11.1.7, 11.2.x before 11.2.4, and 11.3.x before 11.3.1. There is Server-Side Request Forgery (SSRF) via a loopback address to the validate_localhost function in url_blocker.rb.

  • CVE-2023-1725CriMar 30, 2023
    risk 0.64cvss 9.8epss 0.01

    Server-Side Request Forgery (SSRF) vulnerability in Infoline Project Management System allows Server Side Request Forgery. This issue affects Project Management System: before 4.09.31.125.

  • CVE-2022-46973CriMar 3, 2023
    risk 0.64cvss 9.8epss 0.01

    Report v0.9.8.6 was discovered to contain a Server-Side Request Forgery (SSRF) vulnerability.

  • CVE-2022-37938CriMar 1, 2023
    risk 0.64cvss 9.8epss 0.01

    Unauthenticated server side request forgery in HPE Serviceguard Manager

  • CVE-2022-46998CriJan 26, 2023
    risk 0.64cvss 9.8epss 0.01

    An issue in the website background of taocms v3.0.2 allows attackers to execute a Server-Side Request Forgery (SSRF).

  • CVE-2022-39039CriJan 3, 2023
    risk 0.64cvss 9.8epss 0.01

    aEnrich’s a+HRD has inadequate filtering for specific URL parameter. An unauthenticated remote attacker can exploit this vulnerability to send arbitrary HTTP(s) request to launch Server-Side Request Forgery (SSRF) attack, to perform arbitrary system command or disrupt service.

  • CVE-2022-47635CriDec 21, 2022
    risk 0.64cvss 9.8epss 0.01

    Wildix WMS 6 before 6.02.20221216, WMS 5 before 5.04.20221214, and WMS4 before 4.04.45396.23 allows Server-side request forgery (SSRF) via ZohoClient.php.

  • CVE-2022-46364CriDec 13, 2022
    risk 0.64cvss 9.8epss 0.02

    A SSRF vulnerability in parsing the href attribute of XOP:Include in MTOM requests in versions of Apache CXF before 3.5.5 and 3.4.10 allows an attacker to perform SSRF style attacks on webservices that take at least one parameter of any type. 

  • CVE-2022-35508CriDec 4, 2022
    risk 0.64cvss 9.8epss 0.01

    Proxmox Virtual Environment (PVE) and Proxmox Mail Gateway (PMG) are vulnerable to SSRF when proxying HTTP requests between pve(pmg)proxy and pve(pmg)daemon. An attacker with an unprivileged account can craft an HTTP request to achieve SSRF and file disclosure of any files on…

  • CVE-2022-41552CriNov 1, 2022
    risk 0.64cvss 9.8epss 0.01

    Server-Side Request Forgery (SSRF) vulnerability in Hitachi Infrastructure Analytics Advisor on Linux (Data Center Analytics, Analytics probe components), Hitachi Ops Center Analyzer on Linux (Hitachi Ops Center Analyzer detail view, Hitachi Ops Center Analyzer probe components)…