kalcaddle kodbox app.php cover server-side request forgery
CVE-2023-6849
What is CVE-2023-6849?
A vulnerability exists in Kalcaddle Kodbox versions up to 1.48 wherein the 'cover' function in plugins/fileThumb/app.php is susceptible to manipulation. An attacker can exploit this flaw via crafted arguments to perform server-side request forgery, potentially allowing them to access server resources that should be protected. This vulnerability is particularly concerning due to its remote exploitability. It is recommended that users upgrade to version 1.48.04 or later to mitigate this issue. For those affected, applying the patch identified as 63a4d5708d210f119c24afd941d01a943e25334c is crucial.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
kodbox 1.0
kodbox 1.1
kodbox 1.2
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved
