PT-2023-25888 · Unknown · Infodoc Document On-Line Submission/Approval System
Huding
·
Published
2023-07-20
·
Updated
2023-07-28
·
CVE-2023-37290
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
InfoDoc Document On-line Submission and Approval System (affected versions not specified)
Description
The issue arises from insufficient restrictions on available tags within the HTML to PDF conversion function, allowing unauthenticated attackers to load remote or local resources through HTML tags such as
iframe. This enables unauthenticated remote attackers to perform Server-Side Request Forgery (SSRF) attacks, gaining unauthorized access to arbitrary system files and uncovering the internal network topology.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
SSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Infodoc Document On-Line Submission/Approval System