Server Side Request Forgery vulnerability in Vebto Pixie Image Editor 1.4 and 1.7 allows remote attackers to disclose information or execute arbitrary code via the url parameter to Launderer.php.
References
Link | Resource |
---|---|
http://seclists.org/fulldisclosure/2017/Sep/47 | Mailing List Third Party Advisory |
Configurations
Configuration 1 (hide)
|
Information
Published : 2017-09-25 10:29
Updated : 2020-10-02 07:55
NVD link : CVE-2017-12905
Mitre link : CVE-2017-12905
JSON object : View
CWE
CWE-918
Server-Side Request Forgery (SSRF)
Products Affected
vebto
- pixie_-_image_editor