Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:33084
HistoryNov 24, 2021 - 9:51 a.m.

Server-Side Request Forgery (SSRF)

2021-11-2409:51:19
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
8

0.001 Low

EPSS

Percentile

48.0%

concrete5/concrete5 is vulnerable to server-side request forgery. The vulnerability exists through the local IP importing in ‘file.php’ which allows an attacker to read the files from private local LAN servers and exploit the local network apps.

0.001 Low

EPSS

Percentile

48.0%