A Server Side Request Forgery (SSRF) vulnerability in tools/files/importers/remote.php in concrete5 8.2.0 can lead to attacks on the local network and mapping of the internal network, because of URL functionality on the File Manager page.
Metrics
Affected Vendors & Products
References
Link | Providers |
---|---|
https://hackerone.com/reports/243865 |
History
No history.
MITRE
Status: PUBLISHED
Assigner: mitre
Published: 2018-07-09T20:00:00
Updated: 2024-08-05T09:14:47.197Z
Reserved: 2018-07-09T00:00:00
Link: CVE-2018-13790
Vulnrichment
No data.
NVD
Status : Modified
Published: 2018-07-09T20:29:00.957
Modified: 2024-11-21T03:48:00.507
Link: CVE-2018-13790
Redhat
No data.