SSRF vulnerabilities exist in the memos API service `/o/get/httpmeta` that allow unauthenticated and authenticated users to enumerate and read from the internal network. In addition, one SSRF vulnerability leads to a reflected XSS vulnerability, which may allow an attacker complete control over the administrator account.
id: CVE-2024-29028
info:
name: Memos 0.13.2 - Server-Side Request Forgery
author: ritikchaddha
...