PT-2024-17283 · Plextrac · Plextrac

Ianis Bernard

·

Published

2024-12-13

·

Updated

2024-12-13

·

CVE-2024-11836

CVSS v4.0

8.6

High

VectorAV:N/AC:L/AT:P/PR:L/UI:A/VC:H/VI:H/VA:N/SC:H/SI:H/SA:N/U:Red
Name of the Vulnerable Software and Affected Versions PlexTrac versions 1.61.3 through 2.8.1
Description The issue is a Server-Side Request Forgery (SSRF) vulnerability in PlexTrac, allowing requests to internal system resources.
Recommendations For PlexTrac versions 1.61.3 through 2.8.1, update to a version after 2.8.1 to resolve the issue. As a temporary workaround, consider restricting access to internal system resources until a patch is available.

Fix

SSRF

Weakness Enumeration

Related Identifiers

CVE-2024-11836

Affected Products

Plextrac