Server-Side Request Forgery in Wangl1989 MySiteForMe 1.0
CVE-2024-13139
Key Information:
- Vendor
Wangl1989
- Status
- Vendor
- CVE Published:
- 5 January 2025
Badges
What is CVE-2024-13139?
A vulnerability has been identified in version 1.0 of MySiteForMe by wangl1989, specifically in the function doContent located in the FileController. This issue allows an attacker to manipulate the content argument, enabling server-side request forgery (SSRF). The exploit can be triggered remotely, making it a significant concern for security. Public disclosure of this vulnerability raises the potential for exploitation, thereby affecting the integrity and confidentiality of server communications.
Affected Version(s)
mysiteforme 1.0
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- 🟡
Public PoC available
- 👾
Exploit known to exist
Vulnerability published
Vulnerability Reserved