Vulnerability Description
SSRF (Server Side Request Forgery) in tpshop 2.0.5 and 2.0.6 allows remote attackers to obtain sensitive information, attack intranet hosts, or possibly trigger remote command execution via the plugins/payment/weixin/lib/WxPay.tedatac.php fBill parameter.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Tp-Shop | Tpshop | 2.0.5 |
Related Weaknesses (CWE)
References
- http://seclists.org/fulldisclosure/2018/Mar/77Mailing ListThird Party Advisory
- http://seclists.org/fulldisclosure/2018/Mar/77Mailing ListThird Party Advisory
FAQ
What is CVE-2017-16614?
CVE-2017-16614 is a vulnerability with a CVSS score of 9.8 (CRITICAL). SSRF (Server Side Request Forgery) in tpshop 2.0.5 and 2.0.6 allows remote attackers to obtain sensitive information, attack intranet hosts, or possibly trigger remote command execution via the plugin...
How severe is CVE-2017-16614?
CVE-2017-16614 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2017-16614?
Check the references section above for vendor advisories and patch information. Affected products include: Tp-Shop Tpshop.