vendor:
subsonic
by:
John Page a.k.a hyp3rlinx
8.8
CVSS
HIGH
CSRF - Server Side Request Forgery
918
CWE
Product Name: subsonic
Affected Version From: subsonic v6.1.1
Affected Version To: Unknown
Patch Exists: NO
Related CWE: CVE-2017-9413
CPE: a:subsonic:subsonic:6.1.1
Platforms Tested:
2017
CSRF – Server Side Request Forgery in Subsonic
Remote attackers can abuse the Podcast feature of subsonic to launch Server Side Request Forgery attacks on the internal network or to the internet if an authenticated user clicks a malicious link or visits an attacker controlled webpage. SSRF can be used to bypass Firewall restriction on LAN.
Mitigation:
No specific mitigation mentioned