An issue was discovered in the Kitodo.Presentation (aka dif) extension before 2.3.2, 3.x before 3.2.3, and 3.3.x before 3.3.4 for TYPO3. A missing access check in an eID script allows an unauthenticated user to submit arbitrary URLs to this component. This results in SSRF, allowing attackers to view the content of any file or webpage the webserver has access to.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: mitre
Published: 2022-02-19T03:48:57
Updated: 2024-08-03T04:29:01.013Z
Reserved: 2022-02-13T00:00:00
Link: CVE-2022-24980
Vulnrichment
No data.
NVD
Status : Analyzed
Published: 2022-02-19T04:15:07.037
Modified: 2022-03-04T14:19:12.377
Link: CVE-2022-24980
Redhat
No data.