Show filters
409 Total Results
Displaying 51-60 of 409
Sort by:
Attacker Value
Unknown
CVE-2021-36203
Disclosure Date: April 21, 2022 (last updated February 23, 2025)
The affected product may allow an attacker to identify and forge requests to internal systems by way of a specially crafted request.
0
Attacker Value
Unknown
CVE-2022-24871
Disclosure Date: April 20, 2022 (last updated February 23, 2025)
Shopware is an open commerce platform based on Symfony Framework and Vue. In affected versions an attacker can abuse the Admin SDK functionality on the server to read or update internal resources. Users are advised to update to the current version 6.4.10.1. For older versions of 6.1, 6.2, and 6.3, corresponding security measures are also available via a plugin. There are no known workarounds for this issue.
0
Attacker Value
Unknown
CVE-2022-24862
Disclosure Date: April 20, 2022 (last updated February 23, 2025)
Databasir is a team-oriented relational database model document management platform. Databasir 1.01 has Server-Side Request Forgery vulnerability. During the download verification process of a JDBC driver the corresponding JDBC driver download address will be downloaded first, but this address will return a response page with complete error information when accessing a non-existent URL. Attackers can take advantage of this feature for SSRF.
0
Attacker Value
Unknown
CVE-2022-24825
Disclosure Date: April 19, 2022 (last updated February 23, 2025)
Smokescreen is a simple HTTP proxy that fogs over naughty URLs. The primary use case for Smokescreen is to prevent server-side request forgery (SSRF) attacks in which external attackers leverage the behavior of applications to connect to or scan internal infrastructure. Smokescreen also offers an option to deny access to additional (e.g., external) URLs by way of a deny list. There was an issue in Smokescreen that made it possible to bypass the deny list feature by appending a dot to the end of user-supplied URLs, or by providing input in a different letter case. Recommended to upgrade Smokescreen to version 0.0.3 or later.
0
Attacker Value
Unknown
CVE-2022-29153
Disclosure Date: April 19, 2022 (last updated February 23, 2025)
HashiCorp Consul and Consul Enterprise up to 1.9.16, 1.10.9, and 1.11.4 may allow server side request forgery when the Consul client agent follows redirects returned by HTTP health check endpoints. Fixed in 1.9.17, 1.10.10, and 1.11.5.
0
Attacker Value
Unknown
CVE-2022-1037
Disclosure Date: April 18, 2022 (last updated February 23, 2025)
The EXMAGE WordPress plugin before 1.0.7 does to ensure that images added via URLs are external images, which could lead to a blind SSRF issue by using local URLs
0
Attacker Value
Unknown
CVE-2022-27426
Disclosure Date: April 15, 2022 (last updated February 23, 2025)
A Server-Side Request Forgery (SSRF) in Chamilo LMS v1.11.13 allows attackers to enumerate the internal network and execute arbitrary system commands via a crafted Phar file.
0
Attacker Value
Unknown
CVE-2022-26499
Disclosure Date: April 15, 2022 (last updated February 23, 2025)
An SSRF issue was discovered in Asterisk through 19.x. When using STIR/SHAKEN, it's possible to send arbitrary requests (such as GET) to interfaces such as localhost by using the Identity header. This is fixed in 16.25.2, 18.11.2, and 19.3.2.
0
Attacker Value
Unknown
CVE-2021-36202
Disclosure Date: April 07, 2022 (last updated February 23, 2025)
Server-Side Request Forgery (SSRF) vulnerability in Johnson Controls Metasys could allow an authenticated attacker to inject malicious code into the MUI PDF export feature. This issue affects: Johnson Controls Metasys All 10 versions versions prior to 10.1.5; All 11 versions versions prior to 11.0.2.
0
Attacker Value
Unknown
CVE-2020-27375
Disclosure Date: April 07, 2022 (last updated February 23, 2025)
Dr Trust USA iCheck Connect BP Monitor BP Testing 118 version 1.2.1 is vulnerable to Transmitting Write Requests and Chars.
0