SSRF (Server Side Request Forgery) in getRemoteImage.php in Ueditor in Onethink V1.0 and V1.1 allows remote attackers to obtain sensitive information, attack intranet hosts, or possibly trigger remote command execution via the upfile parameter.
References
Link | Resource |
---|---|
http://seclists.org/fulldisclosure/2018/Apr/16 | Exploit Mailing List Third Party Advisory |
Configurations
Configuration 1 (hide)
|
Information
Published : 2018-04-10 08:29
Updated : 2018-05-17 10:34
NVD link : CVE-2017-14323
Mitre link : CVE-2017-14323
JSON object : View
CWE
CWE-918
Server-Side Request Forgery (SSRF)
Products Affected
onethink
- onethink