A vulnerability was found in mccms up to 2.6.5. It has been rated as critical. Affected by this issue is the function pic_api of the file sys/apps/controllers/admin/Comic.php. The manipulation of the argument url leads to server-side request forgery. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. VDB-231506 is the identifier assigned to this vulnerability.
Advisories
Source ID Title
EUVD EUVD EUVD-2023-43911 A vulnerability was found in mccms up to 2.6.5. It has been rated as critical. Affected by this issue is the function pic_api of the file sys/apps/controllers/admin/Comic.php. The manipulation of the argument url leads to server-side request forgery. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. VDB-231506 is the identifier assigned to this vulnerability.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

No history.

Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2024-08-02T06:48:08.197Z

Reserved: 2023-06-14T05:48:15.111Z

Link: CVE-2023-3235

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2023-06-14T07:15:09.510

Modified: 2024-11-21T08:16:45.843

Link: CVE-2023-3235

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses