vendor:
Webedition CMS
by:
Mirabbas Ağalarov
4.1
CVSS
MEDIUM
Blind SSRF
CWE
Product Name: Webedition CMS
Affected Version From: v2.9.8.8
Affected Version To: v2.9.8.8
Patch Exists: NO
Related CWE:
CPE: a:webedition:cms:2.9.8.8
Platforms Tested: Linux
2023
Webedition CMS v2.9.8.8 – Blind SSRF
This exploit allows an attacker to send a malicious request to the server, causing it to make arbitrary requests to other internal or external resources without the user's knowledge or consent.
Mitigation:
To mitigate this vulnerability, the vendor should validate and sanitize all user-supplied input, especially when making requests to external resources.