PT-2024-32990 · Sparkshop · Sparkshop

Rmax2000

·

Published

2024-10-28

·

Updated

2024-10-30

·

CVE-2024-48107

CVSS v3.1

6.5

Medium

VectorAV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions SparkShop versions prior to 1.1.8
Description The issue allows attacks to scan ports on the Intranet or local network where the server resides, attack applications running on the Intranet or local network, or read metadata on the cloud server.
Recommendations For SparkShop versions prior to 1.1.8, update to version 1.1.8 or later to resolve the issue.

Exploit

Fix

SSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2024-48107

Affected Products

Sparkshop