ZeroHour

CVE-2024-48232

PoC
CVSS 3.1
4.9 medium
EPSS
<1%p41
Published
()
Modified
Description

An issue was found in mipjz 5.0.5. In the mipPost method of \app\setting\controller\ApiAdminTool.php, the value of the postAddress parameter is not processed and is directly passed into curl_exec execution and output, resulting in a Server-side request forgery (SSRF) vulnerability that can read server files.

Vendors
mipjz project
Products
mipjz
Weakness
CWE-918
Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N

In the news

No ingested article mentions this CVE yet.