PT-2024-10550 · Unknown+1 · Mapplic Lite+1
Published
2024-10-16
·
Updated
2025-12-19
·
CVE-2012-10018
CVSS v3.1
8.3
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:L |
Name of the Vulnerable Software and Affected Versions
Mapplic versions up to and including 6.1
Mapplic Lite version 1.0
Description
The issue allows attackers to forge requests coming from a vulnerable site's server, potentially leading to an XSS attack if an SVG file is requested. This is made possible by a Server-Side Request Forgery vulnerability.
Recommendations
For Mapplic versions up to and including 6.1, update to a version later than 6.1 to resolve the issue.
For Mapplic Lite version 1.0, consider disabling the plugin until a patched version is available.
Exploit
Fix
SSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Mapplic
Mapplic Lite