A vulnerability, which was classified as critical, was found in lakernote EasyAdmin up to 20240315. Affected is the function thumbnail of the file src/main/java/com/laker/admin/module/sys/controller/IndexController.java. The manipulation of the argument url leads to server-side request forgery. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The patch is identified as 23165d8cb569048c531150f194fea39f8800b8d5. It is recommended to apply a patch to fix this issue. VDB-257718 is the identifier assigned to this vulnerability.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published: 2024-03-22T19:31:11.240Z

Updated: 2024-08-12T15:03:49.285Z

Reserved: 2024-03-22T10:50:04.323Z

Link: CVE-2024-2828

cve-icon Vulnrichment

Updated: 2024-08-01T19:25:42.174Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2024-03-22T20:15:07.440

Modified: 2024-05-17T02:38:33.097

Link: CVE-2024-2828

cve-icon Redhat

No data.