ZeroHour

CVE-2018-1000138

PoC
CVSS 3.1
9.1 critical
EPSS
2%p74
Published
()
Modified
Description

I, Librarian version 4.8 and earlier contains a SSRF vulnerability in "url" parameter of getFromWeb in functions.php that can result in the attacker abusing functionality on the server to read or update internal resources.

Vendors
scilico
Products
i\, librarian
Weakness
CWE-918
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

In the news

No ingested article mentions this CVE yet.