Serendipity Vulnerability Allowing SSRF Bypass via Malformed IP Addresses
CVE-2016-9752
8.6HIGH
What is CVE-2016-9752?
Prior to version 2.0.5 of Serendipity, a vulnerability exists that allows an attacker to bypass Server-Side Request Forgery (SSRF) protections. This is achieved by supplying a malformed IP address, such as http://127.1, or by utilizing a 30x HTTP status code for redirection. This flaw poses significant risks as it could enable unauthorized access to internal services and sensitive data.
