CVE-2018-13790

A Server Side Request Forgery (SSRF) vulnerability in tools/files/importers/remote.php in concrete5 8.2.0 can lead to attacks on the local network and mapping of the internal network, because of URL functionality on the File Manager page.
References
Link Resource
https://hackerone.com/reports/243865 Exploit Third Party Advisory
Advertisement

NeevaHost hosting service

Configurations

Configuration 1 (hide)

cpe:2.3:a:concretecms:concrete_cms:8.2.0:-:*:*:*:*:*:*

Information

Published : 2018-07-09 13:29

Updated : 2021-07-15 13:42


NVD link : CVE-2018-13790

Mitre link : CVE-2018-13790


JSON object : View

CWE
CWE-918

Server-Side Request Forgery (SSRF)

Advertisement

dedicated server usa

Products Affected

concretecms

  • concrete_cms