Lucene search

K
cnvdChina National Vulnerability DatabaseCNVD-2022-08172
HistoryJan 14, 2022 - 12:00 a.m.

PartKeepr server-side request forgery vulnerability

2022-01-1400:00:00
China National Vulnerability Database
www.cnvd.org.cn
3

0.001 Low

EPSS

Percentile

22.0%

PartKeepr is an inventory management software designed primarily for electronic components.PartKeepr suffers from a server-side request forgery vulnerability, which stems from the fact that the ability to upload attachments using a URL when creating a part does not validate whether a request can be made to the local port, and can be exploited by an authenticated attacker to perform SSRF attacks to probe the server’s intranet resources.

CPENameOperatorVersion
partkeepr partkeeprle1.4.0

0.001 Low

EPSS

Percentile

22.0%

Related for CNVD-2022-08172