A Server-Side Request Forgery (SSRF) vulnerability in IPS Community Suite before 4.6.2 allows remote authenticated users to request arbitrary URLs or trigger deserialization via phar protocol when generating class names dynamically. In some cases an exploitation is possible by an unauthenticated user.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published: 2022-06-13T17:45:39

Updated: 2024-08-04T02:44:10.814Z

Reserved: 2021-09-07T00:00:00

Link: CVE-2021-40604

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2022-06-13T18:15:09.787

Modified: 2024-11-21T06:24:26.970

Link: CVE-2021-40604

cve-icon Redhat

No data.