Vulnerability Description
An issue was found in mipjz 5.0.5. In the mipPost method of \app\setting\controller\ApiAdminTool.php, the value of the postAddress parameter is not processed and is directly passed into curl_exec execution and output, resulting in a Server-side request forgery (SSRF) vulnerability that can read server files.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Mipjz Project | Mipjz | 5.0.5 |
Related Weaknesses (CWE)
References
- https://github.com/sansanyun/mipjz/issues/17ExploitIssue Tracking
FAQ
What is CVE-2024-48232?
CVE-2024-48232 is a vulnerability with a CVSS score of 4.9 (MEDIUM). An issue was found in mipjz 5.0.5. In the mipPost method of \app\setting\controller\ApiAdminTool.php, the value of the postAddress parameter is not processed and is directly passed into curl_exec exec...
How severe is CVE-2024-48232?
CVE-2024-48232 has been rated MEDIUM with a CVSS base score of 4.9/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2024-48232?
Check the references section above for vendor advisories and patch information. Affected products include: Mipjz Project Mipjz.