Server-Side Request Forgery vulnerability in SLims version 9.6.0. This vulnerability could allow an authenticated attacker to send requests to internal services or upload the contents of relevant files via the "scrape_image.php" file in the imageURL parameter.
Metrics
Affected Vendors & Products
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-44379 | Server-Side Request Forgery vulnerability in SLims version 9.6.0. This vulnerability could allow an authenticated attacker to send requests to internal services or upload the contents of relevant files via the "scrape_image.php" file in the imageURL parameter. |
Fixes
Solution
The vulnerability has been fixed in the latest version of SLiMS.
Workaround
No workaround given by the vendor.
References
History
Fri, 20 Sep 2024 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: INCIBE
Published:
Updated: 2024-09-20T14:52:59.983Z
Reserved: 2023-07-18T07:17:40.669Z
Link: CVE-2023-3744
Updated: 2024-08-02T07:01:57.471Z
Status : Modified
Published: 2023-10-02T14:15:09.933
Modified: 2024-11-21T08:17:57.917
Link: CVE-2023-3744
No data.
OpenCVE Enrichment
No data.
EUVD