Server side request forgery exists in the runtime application in K2 smartforms 4.6.11 via a modified hostname in an https://*/Identity/STS/Forms/Scripts URL.
Metrics
Affected Vendors & Products
References
Link | Providers |
---|---|
http://www.securityfocus.com/archive/1/542035/100/0/threaded |
History
No history.
MITRE
Status: PUBLISHED
Assigner: mitre
Published: 2018-05-24T13:00:00
Updated: 2024-08-05T07:24:56.217Z
Reserved: 2018-04-10T00:00:00
Link: CVE-2018-9920
Vulnrichment
No data.
NVD
Status : Analyzed
Published: 2018-05-24T13:29:01.430
Modified: 2019-02-27T20:41:42.710
Link: CVE-2018-9920
Redhat
No data.