ZeroHour

CVE-2020-24327

PoC ×2
CVSS 3.1
5.3 medium
EPSS
1%p63
Published
()
Modified
Description

Server Side Request Forgery (SSRF) vulnerability exists in Discourse 2.3.2 and 2.6 via the email function. When writing an email in an editor, you can upload pictures of remote websites.

Vendors
discourse
Products
discourse
Weakness
CWE-918
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N

In the news

No ingested article mentions this CVE yet.