Server-Side Request Forgery in YzmCMS v5.5 by YzmCMS
CVE-2020-20341

7.5HIGH

Key Information:

Vendor
Yzmcms
Status
Vendor
CVE Published:
1 September 2021

Summary

YzmCMS version 5.5 is susceptible to a server-side request forgery (SSRF) vulnerability found in the grab_image() function. This flaw allows unauthorized remote access, potentially exposing sensitive internal resources to attackers. The vulnerability can be exploited if an attacker passes a crafted URL to the grab_image() function, leading to unauthorized actions and data exposure. Proper measures should be implemented to secure the application against such SSRF attacks.

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.