Show filters
1,106 Total Results
Displaying 291-300 of 1,106
Sort by:
Attacker Value
Unknown
CVE-2024-2206
Disclosure Date: March 27, 2024 (last updated February 26, 2025)
An SSRF vulnerability exists in the gradio-app/gradio due to insufficient validation of user-supplied URLs in the `/proxy` route. Attackers can exploit this vulnerability by manipulating the `self.replica_urls` set through the `X-Direct-Url` header in requests to the `/` and `/config` routes, allowing the addition of arbitrary URLs for proxying. This flaw enables unauthorized proxying of requests and potential access to internal endpoints within the Hugging Face space. The issue arises from the application's inadequate checking of safe URLs in the `build_proxy_request` function.
0
Attacker Value
Unknown
CVE-2024-28435
Disclosure Date: March 25, 2024 (last updated February 26, 2025)
The CRM platform Twenty version 0.3.0 is vulnerable to SSRF via file upload.
0
Attacker Value
Unknown
CVE-2024-29190
Disclosure Date: March 22, 2024 (last updated February 26, 2025)
Mobile Security Framework (MobSF) is a pen-testing, malware analysis and security assessment framework capable of performing static and dynamic analysis. In version 3.9.5 Beta and prior, MobSF does not perform any input validation when extracting the hostnames in `android:host`, so requests can also be sent to local hostnames. This can lead to server-side request forgery. An attacker can cause the server to make a connection to internal-only services within the organization's infrastructure. Commit 5a8eeee73c5f504a6c3abdf2a139a13804efdb77 has a hotfix for this issue.
0
Attacker Value
Unknown
CVE-2024-2828
Disclosure Date: March 22, 2024 (last updated February 26, 2025)
A vulnerability, which was classified as critical, was found in lakernote EasyAdmin up to 20240315. Affected is the function thumbnail of the file src/main/java/com/laker/admin/module/sys/controller/IndexController.java. The manipulation of the argument url leads to server-side request forgery. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The patch is identified as 23165d8cb569048c531150f194fea39f8800b8d5. It is recommended to apply a patch to fix this issue. VDB-257718 is the identifier assigned to this vulnerability.
0
Attacker Value
Unknown
CVE-2024-2827
Disclosure Date: March 22, 2024 (last updated February 26, 2025)
A vulnerability, which was classified as critical, has been found in lakernote EasyAdmin up to 20240315. This issue affects some unknown processing of the file /ureport/designer/saveReportFile. The manipulation leads to server-side request forgery. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-257717 was assigned to this vulnerability.
0
Attacker Value
Unknown
CVE-2024-27927
Disclosure Date: March 21, 2024 (last updated February 26, 2025)
RSSHub is an open source RSS feed generator. Prior to version 1.0.0-master.a429472, RSSHub allows remote attackers to use the server as a proxy to send HTTP GET requests to arbitrary targets and retrieve information in the internal network or conduct Denial-of-Service (DoS) attacks. The attacker can send malicious requests to a RSSHub server, to make the server send HTTP GET requests to arbitrary destinations and see partial responses. This may lead to leak the server IP address, which could be hidden behind a CDN; retrieving information in the internal network, e.g. which addresses/ports are accessible, the titles and meta descriptions of HTML pages; and denial of service amplification. The attacker could request the server to download some large files, or chain several SSRF requests in a single attacker request.
0
Attacker Value
Unknown
CVE-2024-24028
Disclosure Date: March 21, 2024 (last updated February 26, 2025)
Server Side Request Forgery (SSRF) vulnerability in Likeshop before 2.5.7 allows attackers to view sensitive information via the avatar parameter in function UserLogic::updateWechatInfo.
0
Attacker Value
Unknown
CVE-2024-25294
Disclosure Date: March 20, 2024 (last updated February 26, 2025)
An SSRF issue in REBUILD v.3.5 allows a remote attacker to obtain sensitive information and execute arbitrary code via the FileDownloader.java, proxyDownload,URL parameters.
0
Attacker Value
Unknown
CVE-2024-27098
Disclosure Date: March 18, 2024 (last updated February 26, 2025)
GLPI is a Free Asset and IT Management Software package, Data center management, ITIL Service Desk, licenses tracking and software auditing. An authenticated user can execute a SSRF based attack using Arbitrary Object Instantiation. This issue has been patched in version 10.0.13.
0
Attacker Value
Unknown
CVE-2024-28752
Disclosure Date: March 15, 2024 (last updated February 26, 2025)
A SSRF vulnerability using the Aegis DataBinding in versions of Apache CXF before 4.0.4, 3.6.3 and 3.5.8 allows an attacker to perform SSRF style attacks on webservices that take at least one parameter of any type. Users of other data bindings (including the default databinding) are not impacted.
0