ZeroHour

CVE-2017-14323

PoC
CVSS 3.0
9.8 critical
EPSS
4%p91
Published
()
Modified
Description

SSRF (Server Side Request Forgery) in getRemoteImage.php in Ueditor in Onethink V1.0 and V1.1 allows remote attackers to obtain sensitive information, attack intranet hosts, or possibly trigger remote command execution via the upfile parameter.

Vendors
onethink
Products
onethink
Weakness
CWE-918
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.