SSRF (Server Side Request Forgery) in getRemoteImage.php in Ueditor in Onethink V1.0 and V1.1 allows remote attackers to obtain sensitive information, attack intranet hosts, or possibly trigger remote command execution via the upfile parameter.
References
Link | Resource |
---|---|
http://seclists.org/fulldisclosure/2018/Apr/16 | Exploit Mailing List Third Party Advisory |
http://seclists.org/fulldisclosure/2018/Apr/16 | Exploit Mailing List Third Party Advisory |
Configurations
Configuration 1 (hide)
|
History
21 Nov 2024, 03:12
Type | Values Removed | Values Added |
---|---|---|
References | () http://seclists.org/fulldisclosure/2018/Apr/16 - Exploit, Mailing List, Third Party Advisory |
Information
Published : 2018-04-10 15:29
Updated : 2024-11-21 03:12
NVD link : CVE-2017-14323
Mitre link : CVE-2017-14323
CVE.ORG link : CVE-2017-14323
JSON object : View
Products Affected
onethink
- onethink
CWE
CWE-918
Server-Side Request Forgery (SSRF)