CVE-2021-27312

CRITICAL9.0EPSS 2.5%

Gleez Cms Server Side Request Forgery (SSRF) vulnerability

Published: 4/3/2024Modified: 4/3/2024
Also known as:GHSA-7mxg-r76p-363g

Description

Server Side Request Forgery (SSRF) vulnerability in Gleez Cms 1.2.0, allows remote attackers to execute arbitrary code and obtain sensitive information via modules/gleez/classes/request.php.

Affected packages (1)

CVSS scores

SourceVersionSeverityVector
osvCVSS 3.1CRITICAL9.0CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H

References (4)