CVE-2021-22958

HIGH8.2EPSS 0.40%

Server-Side Request Forgery vulnerability in concrete5

發布日:2021/10/12修改日:2023/11/8

描述

A Server-Side Request Forgery vulnerability was found in concrete5 < 8.5.5 that allowed a decimal notation encoded IP address to bypass the limitations in place for localhost allowing interaction with local services. Impact can vary depending on services exposed.

受影響套件(1)

CVSS 分數

來源版本嚴重程度向量
osvCVSS 3.1HIGH8.2CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N

參考連結(5)