Server-Side Request Forgery Vulnerability in Envato Elements by Envato
CVE-2024-56275
4.1MEDIUM
Key Information:
- Vendor
- Envato
- Status
- Envato Elements
- Vendor
- CVE Published:
- 7 January 2025
Summary
A Server-Side Request Forgery (SSRF) vulnerability exists in Envato Elements, allowing an attacker to send crafted requests from the server to internal resources, potentially exposing sensitive information or services. This weakness affects versions from n/a through 2.0.14, emphasizing the need for upgrading to mitigate risks.
Affected Version(s)
Envato Elements <= 2.0.14
References
CVSS V3.1
Score:
4.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Rafie Muhammad (Patchstack)