AI Score
Confidence
High
EPSS
Percentile
74.1%
I, Librarian version 4.8 and earlier contains a SSRF vulnerability in “url” parameter of getFromWeb in functions.php that can result in the attacker abusing functionality on the server to read or update internal resources.
github.com/mkucej/i-librarian/blob/9535753a84bc615b210802d4c9542db73368d984/functions.php#L811
github.com/mkucej/i-librarian/issues/120