automad up to 1.10.9 is vulnerable to an authenticated blind server-side request forgery in importUrl
as the import
function on the FileController.php
file was not properly validating the value of the importUrl
argument. This issue may allow attackers to perform a port scan against the local environment or abuse some service.
{ "nvd_published_at": "2023-12-21T17:15:09Z", "cwe_ids": [ "CWE-918" ], "severity": "LOW", "github_reviewed": true, "github_reviewed_at": "2023-12-29T19:32:20Z" }