ZeroHour

CVE-2018-13790

PoC
CVSS 3.1
7.2 high
EPSS
1%p61
Published
()
Modified
Description

A Server Side Request Forgery (SSRF) vulnerability in tools/files/importers/remote.php in concrete5 8.2.0 can lead to attacks on the local network and mapping of the internal network, because of URL functionality on the File Manager page.

Vendors
concretecms
Products
concrete cms
Weakness
CWE-918
Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.