PT-2024-27118 · Unknown · Lylme Spage

Hebing123

·

Published

2024-06-04

·

Updated

2025-07-20

·

CVE-2024-36675

CVSS v3.1

9.1

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions LyLme spage version 1.9.5
Description The issue concerns Server-Side Request Forgery (SSRF) via the get head function. This allows for potential unauthorized access to internal resources.
Recommendations For LyLme spage version 1.9.5, consider disabling the get head function until a patch is available to prevent potential SSRF attacks.

Exploit

Fix

SSRF

Weakness Enumeration

Related Identifiers

CVE-2024-36675

Affected Products

Lylme Spage