hopetree izone lts c011b48 contains a server-side request forgery (SSRF) vulnerability in the active push function as \\apps\\tool\\apis\\bd_push.py does not securely filter user input through push_urls() and get_urls().
Metrics
Affected Vendors & Products
References
Link | Providers |
---|---|
https://github.com/Hopetree/izone/issues/290 |
History
Thu, 21 Nov 2024 17:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Tendcode
Tendcode izone |
|
Weaknesses | CWE-918 | |
CPEs | cpe:2.3:a:tendcode:izone:*:*:*:*:*:*:*:* | |
Vendors & Products |
Tendcode
Tendcode izone |
|
Metrics |
cvssV3_1
|
Fri, 08 Nov 2024 19:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | hopetree izone lts c011b48 contains a server-side request forgery (SSRF) vulnerability in the active push function as \\apps\\tool\\apis\\bd_push.py does not securely filter user input through push_urls() and get_urls(). | |
References |
|
MITRE
Status: PUBLISHED
Assigner: mitre
Published: 2024-11-08T00:00:00
Updated: 2024-11-21T16:34:37.041Z
Reserved: 2024-10-28T00:00:00
Link: CVE-2024-50811
Vulnrichment
Updated: 2024-11-21T16:34:28.134Z
NVD
Status : Awaiting Analysis
Published: 2024-11-08T19:15:06.020
Modified: 2024-11-21T17:15:21.193
Link: CVE-2024-50811
Redhat
No data.