漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
OpenSupports 4.11.0 — SSRF via test imap and smtp endpoints
Vulnerability Description
Two unauthenticated diagnostic endpoints allow arbitrary backend-initiated network connections to an attacker‑supplied destination. Both endpoints are exposed with permission => 'any', enabling unauthenticated SSRF for internal network scanning and service interaction. This issue affects OpenSupports: 4.11.0.
CVSS Information
N/A
Vulnerability Type
服务端请求伪造(SSRF)
Vulnerability Title
OpenSupports 安全漏洞
Vulnerability Description
OpenSupports是OpenSupports开源的一款简单的开源的票务平台。 OpenSupports 4.11.0版本存在安全漏洞,该漏洞源于未经验证的诊断端点允许任意后端网络连接,可能导致服务端请求伪造攻击。
CVSS Information
N/A
Vulnerability Type
N/A