PT-2023-30176 · Espocrm · Espocrm
Asesidaa
·
Publicado
2023-12-05
·
Atualizado
2024-03-06
·
CVE-2023-46736
CVSS v3.1
5.3
Média
| Vetor | AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
EspoCRM versions prior to 8.0.5
Description
The issue is related to a Server-Side Request Forgery (SSRF) vulnerability via the upload image from URL API. Users with access to the
/Attachment/fromImageUrl endpoint can specify a URL to point to an internal host. Although there is a check for content type, it can be bypassed by redirects in some cases. This SSRF can be leveraged to disclose internal information, target internal hosts, and bypass firewalls.Recommendations
For versions prior to 8.0.5, upgrade to release version 8.0.5 or later to address the vulnerability. As a temporary workaround, consider restricting access to the
/Attachment/fromImageUrl endpoint until the issue is resolved. Additionally, be cautious when using the upload image from URL API to minimize the risk of exploitation.Exploit
Correção
SSRF
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Espocrm