MEDIUM · 5.3

CVE-2020-21122

UReport v2.2.9 contains a Server-Side Request Forgery (SSRF) in the designer page which allows attackers to detect intranet device ports.

Vulnerability Description

UReport v2.2.9 contains a Server-Side Request Forgery (SSRF) in the designer page which allows attackers to detect intranet device ports.

CVSS Score

5.3

MEDIUM

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
LOW
Integrity
NONE
Availability
NONE

Affected Products

VendorProductVersions
Ureport ProjectUreport2.2.9

Related Weaknesses (CWE)

References

FAQ

What is CVE-2020-21122?

CVE-2020-21122 is a vulnerability with a CVSS score of 5.3 (MEDIUM). UReport v2.2.9 contains a Server-Side Request Forgery (SSRF) in the designer page which allows attackers to detect intranet device ports.

How severe is CVE-2020-21122?

CVE-2020-21122 has been rated MEDIUM with a CVSS base score of 5.3/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2020-21122?

Check the references section above for vendor advisories and patch information. Affected products include: Ureport Project Ureport.