Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
SoftVision webPDF before 10.0.2 is vulnerable to Server-Side Request Forgery (SSRF). The PDF converter function does not check if internal or external resources are requested in the uploaded files and allows for protocols such as http:// and file:///. This allows an attacker to upload an XML or HTML file in the application, which when rendered to a PDF allows for internal port scanning and Local File Inclusion (LFI).
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
SoftVision webPDF 安全漏洞
Vulnerability Description
SoftVision webPDF是德国SoftVision公司的一个PDF服务平台。 SoftVision webPDF 10.0.2之前版本存在安全漏洞,该漏洞源于PDF转换器功能未检查上传文件中的资源请求,可能导致服务器端请求伪造,进而进行内部端口扫描和本地文件包含。
CVSS Information
N/A
Vulnerability Type
N/A