CVE-2024-24028

Server Side Request Forgery (SSRF) vulnerability in Likeshop before 2.5.7 allows attackers to view sensitive information via the avatar parameter in function UserLogic::updateWechatInfo.
Configurations

No configuration.

History

21 Nov 2024, 08:58

Type Values Removed Values Added
References () https://thanhlo.substack.com/p/khai-thac-lo-hong-cve-2024-24028 - () https://thanhlo.substack.com/p/khai-thac-lo-hong-cve-2024-24028 -

07 Nov 2024, 22:35

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 5.9
CWE CWE-918
Summary
  • (es) La vulnerabilidad de Server Side Request Forgery (SSRF) en Likeshop anterior a 2.5.7 permite a los atacantes ver información confidencial a través del parámetro avatar en la función UserLogic::updateWechatInfo.

21 Mar 2024, 02:52

Type Values Removed Values Added
New CVE

Information

Published : 2024-03-21 02:52

Updated : 2024-11-21 08:58


NVD link : CVE-2024-24028

Mitre link : CVE-2024-24028

CVE.ORG link : CVE-2024-24028


JSON object : View

Products Affected

No product.

CWE
CWE-918

Server-Side Request Forgery (SSRF)