CVE-2018-13790

A Server Side Request Forgery (SSRF) vulnerability in tools/files/importers/remote.php in concrete5 8.2.0 can lead to attacks on the local network and mapping of the internal network, because of URL functionality on the File Manager page.
References
Link Resource
https://hackerone.com/reports/243865 Exploit Third Party Advisory
Configurations

Configuration 1

cpe:2.3:a:concretecms:concrete_cms:8.2.0:-:*:*:*:*:*:*

Information

Published : 2018-07-09 08:29

Updated : 2021-07-15 08:42


NVD link : CVE-2018-13790

Mitre link : CVE-2018-13790

Products Affected
No products.
CWE
CWE-918

Server-Side Request Forgery (SSRF)