Server Side Request Forgery vulnerability in Vebto Pixie Image Editor 1.4 and 1.7 allows remote attackers to disclose information or execute arbitrary code via the url parameter to Launderer.php.
References
Link | Resource |
---|---|
http://seclists.org/fulldisclosure/2017/Sep/47 | Mailing List Third Party Advisory |
http://seclists.org/fulldisclosure/2017/Sep/47 | Mailing List Third Party Advisory |
Configurations
Configuration 1 (hide)
|
History
21 Nov 2024, 03:10
Type | Values Removed | Values Added |
---|---|---|
References | () http://seclists.org/fulldisclosure/2017/Sep/47 - Mailing List, Third Party Advisory |
Information
Published : 2017-09-25 17:29
Updated : 2024-11-21 03:10
NVD link : CVE-2017-12905
Mitre link : CVE-2017-12905
CVE.ORG link : CVE-2017-12905
JSON object : View
Products Affected
vebto
- pixie_-_image_editor
CWE
CWE-918
Server-Side Request Forgery (SSRF)