Server-Side Request Forgery Vulnerability in Envato Elements by Envato
CVE-2024-56275

4.1MEDIUM

Key Information:

Vendor
Envato
Status
Envato Elements
Vendor
CVE Published:
7 January 2025

Summary

A Server-Side Request Forgery (SSRF) vulnerability exists in Envato Elements, allowing an attacker to send crafted requests from the server to internal resources, potentially exposing sensitive information or services. This weakness affects versions from n/a through 2.0.14, emphasizing the need for upgrading to mitigate risks.

Affected Version(s)

Envato Elements <= 2.0.14

References

CVSS V3.1

Score:
4.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Rafie Muhammad (Patchstack)
.