PT-2024-25519 · Linqi · Linqi

Published

2024-05-14

·

Updated

2025-04-28

·

CVE-2024-33864

CVSS v3.1

5.9

Medium

VectorAV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
Name of the Vulnerable Software and Affected Versions linqi versions prior to 1.4.0.1
Description An issue in linqi allows for Server-Side Request Forgery (SSRF) via Document template generation. This can be achieved through remote images in process creation, file inclusion, and PDF document generation using malicious JavaScript.
Recommendations For versions prior to 1.4.0.1, update to version 1.4.0.1 or later to resolve the issue. As a temporary workaround, consider restricting the use of remote images in document template generation and disabling the execution of malicious JavaScript in PDF document generation until a patch is applied.

Fix

SSRF

Weakness Enumeration

Related Identifiers

CVE-2024-33864

Affected Products

Linqi