PT-2024-10905 · Gleez Cms · Gleez Cms

Liotree

·

Published

2024-04-02

·

Updated

2024-08-28

·

CVE-2021-27312

CVSS v3.1

9.4

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L
Name of the Vulnerable Software and Affected Versions Gleez Cms version 1.2.0
Description The issue allows remote attackers to execute arbitrary code and obtain sensitive information via modules/gleez/classes/request.php. This is a Server Side Request Forgery (SSRF) vulnerability.
Recommendations For Gleez Cms version 1.2.0, consider disabling the request.php file in the modules/gleez/classes directory as a temporary workaround until a patch is available. Restrict access to the vulnerable module to minimize the risk of exploitation. Avoid using the vulnerable request.php file in the affected API endpoint until the issue is resolved.

Exploit

Fix

SSRF

Weakness Enumeration

Related Identifiers

CVE-2021-27312
GHSA-7MXG-R76P-363G

Affected Products

Gleez Cms