whoogle-search是一个应用软件。自托管,没有广告,privacy-respecting元搜索引擎 whoogle-search 0.8.4 之前版本存在代码问题漏洞,该漏洞源于app/routes.py 中的 element 方法不会验证用户控制的 src_type 和 element_url 变量,并将它们传递给发送 GET 请求的 send 方法 ,导致服务器端请求伪造。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| benbusby | whoogle-search | < 0.8.4 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
| CVE-2024-22205 | 9.1 CRITICAL | Whoogle Search Server Side Request Forgery vulnerability |
| CVE-2024-22417 | 6.1 MEDIUM | Whoogle Search Cross-site Scripting vulnerability |
| CVE-2024-22204 | 5.3 MEDIUM | Whoogle Search Limited File Write vulnerability |
No comments yet