PT-2023-31076 · Unknown · Commentluv
Yuchen Ji
·
Publicado
2023-12-15
·
Atualizado
2023-12-19
·
CVE-2023-49159
CVSS v3.1
7.5
Alta
| Vetor | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
CommentLuv versions 3.0.4 and earlier
Description
A Server-Side Request Forgery (SSRF) issue has been identified. This allows an attacker to trick the server into making unintended requests, potentially leading to unauthorized access to sensitive data or systems.
Recommendations
For CommentLuv versions 3.0.4 and earlier, update to a version later than 3.0.4 to resolve the issue.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
SSRF
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Commentluv