Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Trovebox version <= 4.0.0-rc6 contains a Server-Side request forgery vulnerability in webhook component that can result in read or update internal resources. This attack appear to be exploitable via HTTP request. This vulnerability appears to have been fixed in after commit 742b8ed.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Trovebox webhook组件安全漏洞
Vulnerability Description
Trovebox是一套开源的图片共享和管理平台。webhook是其中的一个轻量级的事件处理API。 Trovebox 4.0.0-rc6之前版本中的webhook组件存在服务器端请求伪造漏洞。攻击者可通过发送HTTP请求利用该漏洞读取或更新内部资源。
CVSS Information
N/A
Vulnerability Type
N/A