PT-2025-42614 · Illia Cloud · Illia-Builder
Publicado
2025-10-17
·
Atualizado
2025-10-22
·
CVE-2025-60279
CVSS v3.1
9.6
Crítica
| Vetor | AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
Illia Cloud illia-Builder versions prior to 4.8.5
Description
A server-side request forgery (SSRF) flaw exists in Illia Cloud illia-Builder, allowing authenticated users to send arbitrary requests to internal services through the API. An attacker can use this to identify open ports based on response differences and interact with internal services. The issue stems from insufficient validation or sanitization of user-provided input, enabling manipulation of server requests.
Recommendations
Update Illia Cloud illia-Builder to version 4.8.5 or later.
Exploit
Correção
SSRF
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Illia-Builder