Server-Side Request Forgery Vulnerability in CRMEB by ZhongBangKeJi
CVE-2020-21788

4.3MEDIUM

Key Information:

Vendor

Crmeb

Status
Vendor
CVE Published:
24 June 2021

What is CVE-2020-21788?

A server-side request forgery vulnerability exists in CRMEB versions 3.1.0 and above due to improper domain name filtering in the CopyTaobao.php file. This flaw can allow attackers to send unauthorized requests from the server, potentially exposing sensitive internal resources or data. Proper validation measures should be implemented to prevent SSRF attacks and safeguard the integrity of the system.

References

CVSS V3.1

Score:
4.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.