PT-2017-12765 · Vebto · Vebto Pixie Image Editor

Published

2017-09-25

·

Updated

2020-10-02

·

CVE-2017-12905

CVSS v3.1

10

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Vebto Pixie Image Editor versions 1.4 through 1.7
Description A Server Side Request Forgery issue allows remote attackers to disclose information or execute arbitrary code via the url parameter to "Launderer.php" API endpoint.
Recommendations For versions 1.4 through 1.7, avoid using the url parameter in the "Launderer.php" endpoint until the issue is resolved.

Fix

SSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2017-12905

Affected Products

Vebto Pixie Image Editor