Lucene search

K
typo3TYPO3 AssociationTYPO3-EXT-SA-2022-001
HistoryFeb 15, 2022 - 12:00 a.m.

Server-side request forgery in extension "Kitodo.Presentation" (dlf)

2022-02-1500:00:00
TYPO3 Association
typo3.org
28
security
ssrf
kitodo.presentation

EPSS

0.002

Percentile

53.1%

A missing access check in an eID script of the extension allows an unauthenticated user to submit arbitrary URLs to this component. This results in Server-side request forgery allowing users to view the content of any file or webpage the webserver has access to.

EPSS

0.002

Percentile

53.1%

Related for TYPO3-EXT-SA-2022-001