memos vulnerable to an SSRF in /o/get/image
50Vexday Risk Score
Corrija agora. Ela exploração observada pelo VulnCheck e tem exploit funcional público.
ssvc Actcvss 6.1epss 1.1%
da publicação à arma
Publicada no NVD19 de abr.
VulnCheck+524d
probabilidade de exploração
1.1%top 38% das CVEs
exploração observada
simVulnCheck
memos is a privacy-first, lightweight note-taking service. In memos 0.13.2, an SSRF vulnerability exists at the /o/get/image that allows unauthenticated users to enumerate the internal network and retrieve images. The response from the image request is then copied into the response of the current server request, causing a reflected XSS vulnerability. Version 0.22.0 of memos removes the vulnerable file.
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Produtos afetados
usememos · memos