SSRF (Server Side Request Forgery) in getRemoteImage.php in Ueditor in Onethink V1.0 and V1.1 allows remote attackers to obtain sensitive information, attack intranet hosts, or possibly trigger remote command execution via the upfile parameter.
References
Link | Resource |
---|---|
http://seclists.org/fulldisclosure/2018/Apr/16 | Exploit Mailing List Third Party Advisory |
Configurations
Configuration 1 (hide)
|
History
No history.
Information
Published : 2018-04-10 15:29
Updated : 2018-05-17 17:34
NVD link : CVE-2017-14323
Mitre link : CVE-2017-14323
CVE.ORG link : CVE-2017-14323
JSON object : View
Products Affected
onethink
- onethink
CWE
CWE-918
Server-Side Request Forgery (SSRF)