PT-2024-36472 · Unknown · Stirling-Pdf

Summerxxoo

·

Published

2024-12-19

·

Updated

2025-01-02

·

CVE-2024-55082

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Stirling-PDF version 0.35.1
Description A Server-Side Request Forgery (SSRF) issue in the endpoint "http://{your-server}/url-to-pdf" of Stirling-PDF allows attackers to access sensitive information via a crafted request. This enables attackers to obtain confidential data through manipulated requests.
Recommendations For Stirling-PDF version 0.35.1, as a temporary workaround, consider restricting access to the "http://{your-server}/url-to-pdf" endpoint until a patch is available. Avoid using this endpoint with untrusted input to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

SSRF

Weakness Enumeration

Related Identifiers

CVE-2024-55082

Affected Products

Stirling-Pdf