CVE-2021-45851
HIGH7.5EPSS 0.92%Server-Side Request Forgery in FUXA
發布日:2022/3/17修改日:2023/11/8
描述
A Server-Side Request Forgery (SSRF) attack in FUXA 1.1.3 can be carried out leading to the obtaining of sensitive information from the server's internal environment and services, often potentially leading to the attacker executing commands on the server.
受影響套件(1)
- npm/@frangoteam/fuxafrom 0, <= 1.1.3
CVSS 分數
| 來源 | 版本 | 嚴重程度 | 向量 |
|---|---|---|---|
| osv | CVSS 3.1 | HIGH7.5 | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |