PT-2024-15926 · Unknown · 60Indexpage

Glzjin

·

Published

2024-01-26

·

Updated

2024-05-17

·

CVE-2024-0945

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions 60IndexPage versions up to 1.8.5
Description A critical issue has been found in the Parameter Handler component of the affected software, specifically in the file /include/file.php. The manipulation of the url argument leads to server-side request forgery, which can be initiated remotely. The issue has been publicly disclosed.
Recommendations For versions up to 1.8.5, consider restricting access to the vulnerable url argument in the Parameter Handler component to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this issue.

Exploit

Fix

SSRF

Weakness Enumeration

Related Identifiers

CVE-2024-0945

Affected Products

60Indexpage