Server-Side Request Forgery in YzmCMS v5.5 by YzmCMS
CVE-2020-20341
7.5HIGH
Summary
YzmCMS version 5.5 is susceptible to a server-side request forgery (SSRF) vulnerability found in the grab_image() function. This flaw allows unauthorized remote access, potentially exposing sensitive internal resources to attackers. The vulnerability can be exploited if an attacker passes a crafted URL to the grab_image() function, leading to unauthorized actions and data exposure. Proper measures should be implemented to secure the application against such SSRF attacks.
References
CVSS V3.1
Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved