CVE-2017-14323

Source
https://cve.org/CVERecord?id=CVE-2017-14323
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2017-14323.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2017-14323
Published
2018-04-10T15:29:01.080Z
Modified
2026-07-08T05:49:34.307247732Z
Severity
  • 9.8 (Critical) CVSS_V3 - CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
[none]
Details

SSRF (Server Side Request Forgery) in getRemoteImage.php in Ueditor in Onethink V1.0 and V1.1 allows remote attackers to obtain sensitive information, attack intranet hosts, or possibly trigger remote command execution via the upfile parameter.

Database specific
{
    "unresolved_ranges": [
        {
            "extracted_events": [
                {
                    "introduced": "1.0"
                },
                {
                    "last_affected": "1.0"
                }
            ],
            "cpes": [
                "cpe:2.3:a:onethink:onethink:1.0:*:*:*:*:*:*:*"
            ],
            "source": "CPE_STRING",
            "vendor_product": "onethink:onethink"
        }
    ]
}
References

Affected packages

Git / github.com/liu21st/onethink

Affected ranges

Type
GIT
Repo
https://github.com/liu21st/onethink
Events
Database specific
{
    "cpe": "cpe:2.3:a:onethink:onethink:1.1:*:*:*:*:*:*:*",
    "extracted_events": [
        {
            "introduced": "1.1"
        },
        {
            "last_affected": "1.1"
        }
    ],
    "source": "CPE_STRING"
}

Affected versions

1.*
1.1
1.1开发版

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2017-14323.json"