Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
SocialEngine <= 7.8.0 Blind SSRF via /core/link/preview
Vulnerability Description
SocialEngine versions 7.8.0 and prior contain a blind server-side request forgery vulnerability in the /core/link/preview endpoint where user-supplied input passed via the uri request parameter is not sanitized before being used to construct outbound HTTP requests. Authenticated remote attackers can supply arbitrary URLs including internal network addresses and loopback addresses to cause the server to issue HTTP requests to attacker-controlled destinations, enabling internal network enumeration and access to services not intended to be externally reachable.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:N
Vulnerability Type
服务端请求伪造(SSRF)
Vulnerability Title
SocialEngine 代码问题漏洞
Vulnerability Description
SocialEngine是印度SocialEngine公司的一个支持社区互动与社交网络构建的内容管理平台。 SocialEngine 7.8.0及之前版本存在代码问题漏洞,该漏洞源于在/core/link/preview端点中,用户提供的uri请求参数在未清理的情况下被用于构建出站HTTP请求,可能导致经过身份验证的远程攻击者提供任意URL(包括内部网络地址和回环地址),使服务器向攻击者控制的目标发出HTTP请求,从而实现内部网络枚举和访问本不应外部可达的服务。
CVSS Information
N/A
Vulnerability Type
N/A