Lucene search

K
cvelistMitreCVELIST:CVE-2020-13484
HistoryJun 24, 2020 - 2:28 p.m.

CVE-2020-13484

2020-06-2414:28:01
mitre
www.cve.org
1

AI Score

9.4

Confidence

High

EPSS

0.007

Percentile

79.7%

Bitrix24 through 20.0.975 allows SSRF via an intranet IP address in the services/main/ajax.php?action=attachUrlPreview url parameter, if the destination URL hosts an HTML document containing ‘<meta name=“og:image” content="’ followed by an intranet URL.

AI Score

9.4

Confidence

High

EPSS

0.007

Percentile

79.7%

Related for CVELIST:CVE-2020-13484